Insecure Direct Object Reference in Attendize Affects Event Management for Multiple Users
CVE-2026-72547
7.1HIGH
What is CVE-2026-72547?
An insecure direct object reference vulnerability in Attendize enables authenticated event organizers to bulk import attendees into events belonging to other accounts. This occurs through the postImportAttendee endpoint, which loads the target event by ID without verifying that the request is authorized by the original account holder. As a result, an attacker can exploit this flaw to inject attendee data into any event across the platform, circumventing account boundaries and potentially leading to unauthorized access and data manipulation.
Affected Version(s)
Attendize 0 <= 9289acb
