Improper Authorization in Attendize Allows Persistent Survey Injection
CVE-2026-72690

5.4MEDIUM

Key Information:

Vendor

Attendize

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72690?

A vulnerability in Attendize allows an authenticated attacker to exploit improper authorization mechanisms. Specifically, through a flaw in the postCreateEventQuestion method, an attacker can inject persistent mandatory survey questions into events managed by other organizers. This is possible via the POST /event/{event_id}/question/create endpoint, where the absence of tenant isolation enables cross-tenant writes. As a result, the original event organizer cannot delete or modify the injected questions since their account-scoped path does not recognize questions owned by other tenants. This vulnerability poses significant risks to event privacy and data integrity, making it imperative for users to apply respective security patches and maintain updated system configurations.

Affected Version(s)

Attendize 0 <= 9289acb

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov (Mahadsec)
.