CVE-2026-101267

EUVD-2026-88748
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
rami.ioCNA
2.7 LOW
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pretixpretix
0.0 ≤
𝑥
< 2026.5.5
CNA
pretixpretix
2026.6.0 ≤
𝑥
< 2026.6.2
CNA
pretixpretix
2026.7.0 ≤
𝑥
< 2026.7.1
CNA