CVE-2026-101267 PUBLISHED

Revenue information leak

Assigner: rami.io
Reserved: 28.09.2026 Published: 29.09.2026 Updated: 29.09.2026

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U
CVSS Score: 2.7

Product Status

Vendor pretix
Product pretix
Versions Default: unaffected
  • affected from 0.0 to 2026.5.5 (excl.)
  • affected from 2026.6.0 to 2026.6.2 (excl.)
  • affected from 2026.7.0 to 2026.7.1 (excl.)

Credits

  • Wenhao Wu of Southeast University finder

References