CVE-2026-101267
2.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U
Summary
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pretix | pretix | 0.0 < 2026.5.5 | affected |
| pretix | pretix | 2026.6.0 < 2026.6.2 | affected |
| pretix | pretix | 2026.7.0 < 2026.7.1 | affected |
Weaknesses
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.