Insecure Direct Object Reference in Attendize Affects Event Management Functionality
CVE-2026-72546

7.1HIGH

Key Information:

Vendor

Attendize

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72546?

A vulnerability exists in Attendize that permits authenticated event organisers to exploit insecure direct object references through the postInviteAttendee endpoint. By forging requests, an attacker could manipulate event data and financial records by targeting events not belonging to their account. This flaw arises from the lack of proper query scoping to the authenticated organiser, enabling unauthorized access and modification of sensitive information across different user accounts.

Affected Version(s)

Attendize 0 <= 9289acb

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov (Mahadsec)
.