Improper Authorization in Attendize Allows Persistent Survey Injection
CVE-2026-72690
What is CVE-2026-72690?
A vulnerability in Attendize allows an authenticated attacker to exploit improper authorization mechanisms. Specifically, through a flaw in the postCreateEventQuestion method, an attacker can inject persistent mandatory survey questions into events managed by other organizers. This is possible via the POST /event/{event_id}/question/create endpoint, where the absence of tenant isolation enables cross-tenant writes. As a result, the original event organizer cannot delete or modify the injected questions since their account-scoped path does not recognize questions owned by other tenants. This vulnerability poses significant risks to event privacy and data integrity, making it imperative for users to apply respective security patches and maintain updated system configurations.
Affected Version(s)
Attendize 0 <= 9289acb
