CVE-2026-101267 Details
Description
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
A vulnerability in Pretix allows low-privileged users with access to an event, but not to the event's orders, to access certain information. This includes the number of attendees and the total revenue generated. The issue arises from a missing permission check, enabling unauthorized information extraction.
Users are advised to update to Pretix versions 2026.7.1, 2026.6.2, or 2026.5.5, all of which include the necessary fix. For those using the Pretix Hosted service, the vulnerability has already been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260929-release-2026-7-1/ | rami.io | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| pretix | >= 2026, < 2026.7.1 >= 2026, < 2026.6.2 >= 2026, < 2026.5.5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | rami.io |
Volerion