CVE-2026-101267
EUVD-2026-8874829.09.2026, 13:17
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| pretix | pretix | 0.0 ≤ 𝑥 < 2026.5.5 | CNA |
| pretix | pretix | 2026.6.0 ≤ 𝑥 < 2026.6.2 | CNA |
| pretix | pretix | 2026.7.0 ≤ 𝑥 < 2026.7.1 | CNA |
Common Weakness Enumeration