Impact
The vulnerability arises because Shelf, a multi‑tenant platform for tracking physical assets, allowed endpoints to accept entity IDs from request payloads without verifying that those IDs belonged to the caller's organization. An authenticated user in one organization who knows or obtains an ID from another organization can perform operations such as reading or attaching that other organization's assets, tags, custodians, bookings, QR codes, and audit data, thereby breaching tenant isolation. Additionally, a loader‑only restriction on personal‑workspace bookings could be bypassed with a crafted POST request. This cross‑tenant IDOR existed in all releases before version 1.20.2; the issue was fixed with that release.
Affected Systems
The Shelf‑nu platform (shelf.nu) is affected. All releases older than version 1.20.2 contain this flaw. The issue was fixed in release 1.20.2, which introduces proper organization ID checks.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑medium risk, and the EPSS score of less than 1% suggests that exploitation is unlikely but still possible. Shelf‑nu is not listed in CISA’s KEV catalog, meaning no publicly discovered exploits are recorded. Attackers must be authenticated and know or obtain a victim organization’s entity ID to exploit this cross‑tenant IDOR. The impact consists of exposing or attaching confidential data across organizations, compromising confidentiality and integrity, with no known denial of service or privilege escalation.
OpenCVE Enrichment