Back to overview

CVE-2026-18028

LOW
2.3
CVSS 4.0
Description
The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the given event. An attacker could use a well-timed request to create products, quotas, set bank transfer configuration, or connect a stripe account to an event they do not have access to.

Metadata

CVE ID
CVE-2026-18028
State
PUBLISHED
Assigner
rami.io
Reserved
2026-07-28 07:28 UTC
Published
2026-07-28 10:39 UTC
Last updated
2026-07-28 12:38 UTC
Primary CWE
CWE-639
CWE-639 Authorization bypass through User-Controlled key
Vendor / Product
pretix GmbH / pretix
Sources
cve.org  ·  NVD

Severity & Metrics

2.3 LOW CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
pretix GmbH pretix 0 < 2026.4.6, 2026.5.0 < 2026.5.4, 2026.6.0 < 2026.6.1
Weakness (CWE)
CWESourceDescription
CWE-639 cna CWE-639 Authorization bypass through User-Controlled key
CVSS scores (1)
ScoreSeverityVersionSourceVector
2.3 LOW 4.0 cna CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Back to overview