CVE-2026-33530 affects InvenTree, an open-source inventory management system, in versions prior to 1.2.6. This vulnerability allows authenticated users to exfiltrate sensitive database information by exploiting unvalidated 'filters' parameters in bulk API operations. Rated Medium with a CVSS score of 6.5, it poses a high confidentiality risk through network-based, low-complexity attacks requiring low privileges. There is currently no evidence of active exploitation, no public exploit code is available, and community attention remains low. Organizations using InvenTree should update to version 1.2.6 or higher to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.6CPE matchmatch criteria | cpe:2.3:a:inventree_project:inventree:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.