API Authentication and File Upload Issues in Pretix by Pretix
CVE-2026-101269

2.3LOW

Key Information:

Vendor

Pretix

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-101269?

The Pretix platform experiences a vulnerability in its API where the authentication mechanism for files uploaded via the API does not function correctly. This issue arises from the reliance on a single session token for all token-based API users, leading to potential misuse of session tokens. Although API-uploaded files are associated with unique UUIDs and have a limited lifespan of one day, the failure to properly enforce separate authentication tokens undermines the intended protection mechanisms. This could expose the system to unauthorized access scenarios.

Affected Version(s)

pretix 0.0 < 2026.5.5

pretix 2026.6.0 < 2026.6.2

pretix 2026.7.0 < 2026.7.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wenhao Wu of Southeast University
.