CVE-2026-47697

Source
https://cve.org/CVERecord?id=CVE-2026-47697
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47697.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47697
Aliases
  • GHSA-r46p-gfrp-xxgq
Published
2026-07-21T20:53:19.260Z
Modified
2026-07-25T03:56:43.460891870Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Shelf has cross-organization IDOR: authenticated users could read/attach another workspace's assets, tags, custodians, bookings, QR codes and audit data
Details

Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, several endpoints accepted entity IDs from request input and connect-ed / read / updated them without verifying the IDs belonged to the caller's organization. An authenticated user in Org A who knew or obtained an ID belonging to Org B could act on Org B's data across organization boundaries (a cross-tenant IDOR). A loader-only restriction on personal-workspace bookings was also bypassable via a crafted POST. Version 1.20.2 patches the issue. No known workarounds are available.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47697.json"
}
References

Affected packages

Git / github.com/shelf-nu/shelf.nu

Affected ranges

Type
GIT
Repo
https://github.com/shelf-nu/shelf.nu
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.20.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

shelf@1.*
shelf@1.0.0
shelf@1.1.0
shelf@1.1.1
shelf@1.1.2
shelf@1.10.1
shelf@1.10.10
shelf@1.10.2
shelf@1.10.3
shelf@1.10.4
shelf@1.10.5
shelf@1.10.6
shelf@1.10.7
shelf@1.10.8
shelf@1.10.9
shelf@1.11.0
shelf@1.11.1
shelf@1.11.2
shelf@1.11.3
shelf@1.11.4
shelf@1.11.5
shelf@1.12
shelf@1.12.1
shelf@1.12.2
shelf@1.12.3
shelf@1.12.4
shelf@1.12.5
shelf@1.12.6
shelf@1.13.0
shelf@1.13.1
shelf@1.14.0
shelf@1.14.1
shelf@1.14.2
shelf@1.14.3
shelf@1.15.0
shelf@1.15.1
shelf@1.16.0
shelf@1.16.1
shelf@1.16.2
shelf@1.16.3
shelf@1.16.4
shelf@1.17.0
shelf@1.17.1
shelf@1.17.2
shelf@1.18.0
shelf@1.18.1
shelf@1.18.2
shelf@1.18.3
shelf@1.18.4
shelf@1.18.5
shelf@1.18.6
shelf@1.19.0
shelf@1.2.0
shelf@1.2.1
shelf@1.2.10
shelf@1.2.2
shelf@1.2.3
shelf@1.2.4
shelf@1.2.5
shelf@1.2.6
shelf@1.2.7
shelf@1.2.8
shelf@1.2.9
shelf@1.20.0
shelf@1.20.1
shelf@1.3.0
shelf@1.3.1
shelf@1.4.0
shelf@1.4.1
shelf@1.5.0
shelf@1.5.1
shelf@1.5.2
shelf@1.5.3
shelf@1.5.4
shelf@1.6.0
shelf@1.6.1
shelf@1.6.2
shelf@1.7.0
shelf@1.7.1
shelf@1.7.2
shelf@1.7.3
shelf@1.8.0
shelf@1.8.1
shelf@1.8.2
shelf@1.9.0
shelf@1.9.1
shelf@1.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47697.json"