CVE-2026-57536 Details
Description
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
A vulnerability exists in the Pretix payment integration with Mollie, where the system fails to properly validate payment status responses. This flaw allows an attacker to reuse a successful payment status response from one transaction and apply it to a different payment, potentially gaining access to multiple valid tickets with just one payment. The issue affects all currently supported versions of Pretix, except for the fixed version 2026.5.2.
Users are advised to update to Pretix version 2026.5.2, 2026.4.4, or 2026.3.4. For those using the Pretix Mollie plugin, version 2.5.6 is available. Instructions for updating can be found on the Pretix blog.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ | rami.io | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-841 | Improper Enforcement of Behavioral Workflow | rami.io |
Affected Products
| Product | Versions |
|---|---|
| pretix-mollie | >= 2026, < 2026.5.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | rami.io |
Volerion