Back to CVE List

CVE-2026-18028

Vulnerability Description

The "quick setup" view presented to users after they first create an
event allows to set up the most critical parts of an event in just a few
clicks. This view did not properly check that the user has permission
to change configuration for the given event. An attacker could use a
well-timed request to create products, quotas, set bank transfer
configuration, or connect a stripe account to an event they do not have
access to.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-639
Source
NVD
Vendor
pretix GmbH
Product
pretix

External References

Discussion (0)

Add Comment

No comments yet. Be the first!