Improper Access Control in alf.io Ticket Reservation System
CVE-2026-50165

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-50165?

The alf.io ticket reservation system suffers from an improper access control vulnerability which allows organization owners to inadvertently access sensitive system-level configuration secrets. In versions prior to 2.0-M5-2605, organization/event scoped 'single configuration' endpoints inadvertently expose secrets intended solely for administrators. By exploiting these endpoints, an organization owner can obtain critical information such as system API keys, potentially jeopardizing the security of the entire platform. This issue has been remediated in version 2.0-M5-2605.

Affected Version(s)

alf.io < 2.0-M5-2606

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.