CVE-2026-101268: Pretix

Low severity, CVSS 1.7. EPSS: 0.2% chance of exploitation in the next 30 days.

If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.

Affected products

  • Pretix Pretix: from 0.0, before 2026.5.5 (fixed in 2026.5.5); from 2026.6.0, before 2026.6.2 (fixed in 2026.6.2); from 2026.7.0, before 2026.7.1 (fixed in 2026.7.1)

Published 2026-09-29. Last modified 2026-09-29.