CVE-2026-13223 PUBLISHED

Insufficient validation of payment status in pretix-computop

Assigner: rami.io
Reserved: 24.06.2026 Published: 25.06.2026 Updated: 25.06.2026

Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
CVSS Score: 6.3

Product Status

Vendor pretix
Product pretix-computop
Versions Default: unaffected
  • affected from 0 to 1.3.2 (excl.)

Credits

  • Deepjyoti Roy finder

References

Problem Types

  • CWE-841 Improper enforcement of behavioral workflow CWE

Impacts

  • CAPEC-21 Exploitation of Trusted Identifiers