CVE-2026-61745: Inventree
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other machine management operations. Any authenticated user who lacks the ADMIN role, including a warehouse user with only the STOCK role, can cause MachineRestart to invoke registry.restart_machine() for any registered machine, resetting its status and interrupting active printing, scanning, or other machine operations. This issue is fixed in version 1.4.0.
Affected products
- Inventree Inventree: before 1.4.0 (fixed in 1.4.0)
Published 2026-09-21. Last modified 2026-09-23.