CVE-2026-13222

EUVD-2026-39414
Our payment integration with Oppwa-based payment methods did not 
properly validate payment status responses. An attacker could use a 
successful payment status response from one payment and supply it to the
 system for a different payment, gaining access to multiple valid 
tickets with only one payment.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---