7.7

CVE-2026-13602

Session takeover vulnerability

We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:







  *  


The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay
 contain a code path that is intended for the transport of session 
parameters from a tab with isolated cookies (e.g. in the pretix widget) 
to a new tab. For this purpose, a set of session parameters is 
cryptographically signed and then passed to the new tab as a URL 
parameter. The plugins perform no further validation of the session 
parameters, other than the cryptographic signature being valid. This is 
fixed with the releases issued today by strictly validating that no 
session parameters outside of the scope of the respective plugin may be 
set.




  *  


An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer
 headers for outgoing links to prevent leakage of secrets in URLs. This 
redirect page also requires cryptographically signed parameters. 
Unfortunately, it uses the same key and salt for the signature as the 
previously mentioned feature in the payment integration plugins. A 
motivated attacker with access to at least one event in the backend can 
trick the system into cryptographically signing arbitrary content using 
specially crafted links. In combination with the previous issue, the 
attacker could use this to set and modify arbitrary parameters on their 
user session by injecting the signed parameters into the feature of the 
payment providers. This is fixed with the releases issued today by using
 different salts for the signature for each plugin and feature.




  *  


A third, unrelated feature in the core system is used for admin users
 to act on behalf of another user, mostly for debugging purposes. With 
being able to insert arbitrary parameters into a session, an attacker 
can abuse this feature to change their session from their actual user to
 any user in the system by guessing a valid user ID. This is fixed with
 the release today by requiring unguessable information to be contained 
in the session of the user to switch to.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpretix
Produkt pretix
Default Statusunaffected
Version 4.14.0
Version < 2026.3.5
Status affected
Version 2026.4.0
Version < 2026.4.5
Status affected
Version 2026.5.0
Version < 2026.5.3
Status affected
Herstellerpretix
Produkt pretix-mollie
Default Statusunaffected
Version 0
Version < 2.5.7
Status affected
Herstellerpretix
Produkt pretix-oppwa
Default Statusunaffected
Version 0
Version < 1.4.4
Status affected
Herstellerpretix
Produkt pretix-bitpay
Default Statusunaffected
Version 0
Version < 1.5.3
Status affected
Herstellerpretix
Produkt pretix-payone
Default Statusunaffected
Version 0
Version < 1.4.3
Status affected
Herstellerpretix
Produkt pretix-secuconnect
Default Statusunaffected
Version 0
Version < 1.0.4
Status affected
Herstellerpretix
Produkt pretix-sofort
Default Statusunaffected
Version 0
Version < 1.4.2
Status affected
Herstellerpretix
Produkt pretix-saferpay
Default Statusunaffected
Version 0
Version < 1.6.3
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.192
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
655498c3-6ec5-4f0b-aea6-853b334d05a6 7.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-323 Reusing a Nonce, Key Pair in Encryption

Nonces should be used for the present occasion and only once.

https://pretix.eu/about/en/blog/20260701-release-2026-5-3/