CVE-2026-101271 Details
Description
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
A vulnerability exists in Pretix where OAuth access tokens remain valid for their entire lifespan, even if the associated application (OAuth client) is manually disabled. This issue affects all currently supported versions of Pretix.
Users are advised to update to Pretix versions 2026.7.1, 2026.6.2, or 2026.5.5, all of which include the necessary fix. For those using Pretix Hosted, the vulnerability has already been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260929-release-2026-7-1/ | rami.io | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| pretix | >= 2026, < 2026.7.1 >= 2026, < 2026.6.2 >= 2026, < 2026.5.5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | rami.io |
Volerion