CVE-2026-61744

CVE-2026-61744 published: InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthenticatedOrReadScope a...

View full NVD advisory → ← Back to CVE watch