CVE-2026-101266 Details
Description
A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.
A logic flaw has been identified in the checkout process of Pretix, allowing users to bypass validation checks by skipping entire steps during the check-in process. This vulnerability affects all currently supported versions of Pretix, except for the recently released updates in version 2026.7.1, 2026.6.2, and 2026.5.5.
Users are advised to update to Pretix versions 2026.7.1, 2026.6.2, or 2026.5.5. For those using the Pretix Hosted service, the vulnerability has already been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260929-release-2026-7-1/ | rami.io | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | rami.io |
Affected Products
| Product | Versions |
|---|---|
| pretix | >= 2026, < 2026.7.1 >= 2026, < 2026.6.2 >= 2026, < 2026.5.5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | rami.io |
Volerion