Information Disclosure Vulnerability in Pretix Event Management System
CVE-2026-101267
2.7LOW
What is CVE-2026-101267?
A permission oversight in the Pretix Event Management System permits low-privileged users who can access an event to retrieve sensitive details, such as the number of attendees and total revenue, without permissions to view the event's associated orders. This could potentially lead to unauthorized access to sensitive business information, highlighting the importance of implementing proper access controls.
Affected Version(s)
pretix 0.0 < 2026.5.5
pretix 2026.6.0 < 2026.6.2
pretix 2026.7.0 < 2026.7.1
