Insecure Direct Object Reference in Attendize Affects Event Management for Multiple Users
CVE-2026-72547

7.1HIGH

Key Information:

Vendor

Attendize

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72547?

An insecure direct object reference vulnerability in Attendize enables authenticated event organizers to bulk import attendees into events belonging to other accounts. This occurs through the postImportAttendee endpoint, which loads the target event by ID without verifying that the request is authorized by the original account holder. As a result, an attacker can exploit this flaw to inject attendee data into any event across the platform, circumventing account boundaries and potentially leading to unauthorized access and data manipulation.

Affected Version(s)

Attendize 0 <= 9289acb

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov (Mahadsec)
.