CVE-2026-61745

CVE-2026-61745 published: InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other machine management o...

View full NVD advisory → ← Back to CVE watch