CVE-2026-2415 Details
Description
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. This mechanism contained two security-relevant bugs: * It was possible to exfiltrate information about the pretix system through specially crafted placeholder names such as {{event.__init__.__code__.co_filename}}. This way, an attacker with the ability to control email templates (usually every user of the pretix backend) could retrieve sensitive information from the system configuration, including even database passwords or API keys. pretix does include mechanisms to prevent the usage of such malicious placeholders, however due to a mistake in the code, they were not fully effective for the email subject. * Placeholders in subjects and plain text bodies of emails were wrongfully evaluated twice. Therefore, if the first evaluation of a placeholder again contains a placeholder, this second placeholder was rendered. This allows the rendering of placeholders controlled by the ticket buyer, and therefore the exploitation of the first issue as a ticket buyer. Luckily, the only buyer-controlled placeholder available in pretix by default (that is not validated in a way that prevents the issue) is {invoice_company}, which is very unusual (but not impossible) to be contained in an email subject template. In addition to broadening the attack surface of the first issue, this could theoretically also leak information about an order to one of the attendees within that order. However, we also consider this scenario very unlikely under typical conditions. Out of caution, we recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file.
A vulnerability exists in Pretix email templates that allows for the unsafe evaluation of placeholders, which can be exploited to exfiltrate sensitive information from the system. This issue affects all supported versions of Pretix after an estimated version 4.16.0 and prior to 2026.1.1, except for the fixed versions 2026.1.1, 2025.10.2, and 2025.9.4. The vulnerability arises from a flaw in the placeholder evaluation mechanism, which failed to properly sanitize placeholder names in the email subject, allowing attackers to inject malicious placeholders that could retrieve confidential data such as database passwords or API keys. Additionally, the vulnerability is compounded by a double evaluation of placeholders in email subjects and plain text bodies, which could potentially leak order information to other attendees.
Users are advised to update to Pretix versions 2026.1.1, 2025.10.2, or 2025.9.4. For those using Pretix Enterprise plugins, updates are available for the affected plugins: pretix-doistep (version 1.3.2) and pretix-newsletter (versions 2.0.1 and 1.6.3).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260216-release-2026-1-1/ | rami.io | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-627 | Dynamic Variable Evaluation | rami.io |
Affected Products
| Product | Versions |
|---|---|
| pretix pretix | >= 4.16.0, < 2026.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | rami.io |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 13, 2026 | Initial Analysis | [email protected] |
| Feb 16, 2026 | New CVE Received | rami.io |