CVE-2026-13223

EUVD-2026-39413
Our payment integration with Computop-based payment methods did not 
properly validate payment status responses. An attacker could use a 
successful payment status response from one payment and supply it to the
 system for a different payment, gaining access to multiple valid 
tickets with only one payment.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---