Improper Access Control in alf.io Ticket Reservation System
CVE-2026-50165
7.1HIGH
What is CVE-2026-50165?
The alf.io ticket reservation system suffers from an improper access control vulnerability which allows organization owners to inadvertently access sensitive system-level configuration secrets. In versions prior to 2.0-M5-2605, organization/event scoped 'single configuration' endpoints inadvertently expose secrets intended solely for administrators. By exploiting these endpoints, an organization owner can obtain critical information such as system API keys, potentially jeopardizing the security of the entire platform. This issue has been remediated in version 2.0-M5-2605.
Affected Version(s)
alf.io < 2.0-M5-2606
