CVE-2026-101269 Details
Description
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.
A vulnerability exists in Pretix due to incorrect session validation for files uploaded via the API. The same session token is used for all token-based API users, which undermines the intended authentication mechanism. Although API-uploaded files are only accessible for one day and referenced by randomly generated UUIDs, this flaw renders the added protection ineffective.
Users are advised to update to Pretix versions 2026.7.1, 2026.6.2, or 2026.5.5, all of which include the necessary fix. For those using the hosted Pretix service, the vulnerability has already been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260929-release-2026-7-1/ | rami.io | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| pretix | >= 2026, < 2026.7.1 >= 2026, < 2026.6.2 >= 2026, < 2026.5.5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | rami.io |
Volerion