CVE-2026-101271

EUVD-2026-88754
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
rami.ioCNA
2.1 LOW
NETWORK
HIGH
LOW
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pretixpretix
0.0 ≤
𝑥
< 2026.5.5
CNA
pretixpretix
2026.6.0 ≤
𝑥
< 2026.6.2
CNA
pretixpretix
2026.7.0 ≤
𝑥
< 2026.7.1
CNA