Configuration Permission Bypass in Event Management Product by Pretix
CVE-2026-18028
2.3LOW
What is CVE-2026-18028?
In Pretix's event management software, a flaw in the 'quick setup' view allows users to configure critical event details without adequate permission checks. This oversight presents a risk where an unauthorized attacker could exploit the system to create products, define quotas, set up bank transfer configurations, or link a Stripe account to events beyond their access rights. Adequate measures must be implemented to ensure users can only modify configurations for events they are authorized to manage.
Affected Version(s)
pretix 0 < 2026.4.6
pretix 2026.5.0 < 2026.5.4
pretix 2026.6.0 < 2026.6.1
