CVE-2026-101267: Pretix
Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
Affected products
- Pretix Pretix: from 0.0, before 2026.5.5 (fixed in 2026.5.5); from 2026.6.0, before 2026.6.2 (fixed in 2026.6.2); from 2026.7.0, before 2026.7.1 (fixed in 2026.7.1)
Published 2026-09-29. Last modified 2026-09-29.