CVE-2026-101269
EUVD-2026-8875129.09.2026, 13:17
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| pretix | pretix | 0.0 ≤ 𝑥 < 2026.5.5 | CNA |
| pretix | pretix | 2026.6.0 ≤ 𝑥 < 2026.6.2 | CNA |
| pretix | pretix | 2026.7.0 ≤ 𝑥 < 2026.7.1 | CNA |
Common Weakness Enumeration