CVE-2026-101267

Summary

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.

Affected Software

VendorProductVersion RangeStatus
pretixpretix0.0 < 2026.5.5affected
pretixpretix2026.6.0 < 2026.6.2affected
pretixpretix2026.7.0 < 2026.7.1affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References