What is CVE-2026-47697?
An insufficient access control vulnerability was identified in the Shelf asset-tracking platform, where prior to version 1.20.2, several endpoints failed to verify that entity IDs from requests belonged to the caller's organization. This could allow unauthorized cross-tenant data access. Upgrading to version 1.20.2 is recommended.
Azərbaycanca: Shelf platformasında çox-icarəçili məlumat izolyasiyası zəifliyi aşkarlanıb; 1.20.2 versiyasından əvvəl bəzi endpoint-lər sorğudan gələn entity ID-lərini çağırışçının təşkilatına aidiyyətini yoxlamadan emal edir. Bu, təcavüzkarın digər təşkilatların məlumatlarına icazəsiz giriş əldə etməsinə səbəb ola bilər. Versiya 1.20.2-yə yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What security issue can CVE-2026-47697 cause in the Shelf platform?
This vulnerability leads to a breakdown of data isolation in a multi-tenant environment. An attacker could manipulate entity IDs to gain unauthorized access to data belonging to other organizations.
Which version should be upgraded to in order to fix CVE-2026-47697?
The vulnerability is fixed in version 1.20.2 of the Shelf platform. Upgrading to this version or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.