2.7
CVE-2026-101267
- EPSS 0.24%
- Veröffentlicht 29.09.2026 13:17:49
- Zuletzt bearbeitet 29.09.2026 21:28:02
- Erkennungen
Revenue information leak
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpretix
≫
Produkt
pretix
Default Statusunaffected
Version
0.0
Version <
2026.5.5
Status
affected
Version
2026.6.0
Version <
2026.6.2
Status
affected
Version
2026.7.0
Version <
2026.7.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 655498c3-6ec5-4f0b-aea6-853b334d05a6 | 2.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://pretix.eu/about/en/blog/20260929-release-2026-7-1/