2.3

CVE-2026-18028

Missing authorization check in event quick setup view

The "quick setup" view presented to users after they first create an 
event allows to set up the most critical parts of an event in just a few
 clicks. This view did not properly check that the user has permission 
to change configuration for the given event. An attacker could use a 
well-timed request to create products, quotas, set bank transfer 
configuration, or connect a stripe account to an event they do not have 
access to.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpretix GmbH
Produkt pretix
Default Statusunaffected
Version 0
Version < 2026.4.6
Status affected
Version 2026.5.0
Version < 2026.5.4
Status affected
Version 2026.6.0
Version < 2026.6.1
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.11
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
655498c3-6ec5-4f0b-aea6-853b334d05a6 2.3 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://pretix.eu/about/en/blog/20260728-release-2026-6-1/