CVE-2026-101271: Pretix

Low severity, CVSS 2.1. EPSS: 0.2% chance of exploitation in the next 30 days.

OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.

Affected products

  • Pretix Pretix: from 0.0, before 2026.5.5 (fixed in 2026.5.5); from 2026.6.0, before 2026.6.2 (fixed in 2026.6.2); from 2026.7.0, before 2026.7.1 (fixed in 2026.7.1)

Published 2026-09-29. Last modified 2026-09-29.