CVE-2026-18029

EUVD-2026-49752
Our payment integration with GiroCheckout did not properly validate 
payment status responses. An attacker could use a successful payment 
status response from one payment and supply it to the system for a 
different payment, gaining access to multiple valid tickets with only 
one payment.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---