CVE-2026-18028
Missing authorization check in event quick setup view
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the given event. An attacker could use a well-timed request to create products, quotas, set bank transfer configuration, or connect a stripe account to an event they do not have access to.
| CWE | CWE-639 |
| Vendor | pretix gmbh |
| Product | pretix |
| Published | Jul 28, 2026 |
| Last Updated | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for pretix gmbh pretix
Be the first to know when new unknown vulnerabilities affecting pretix gmbh pretix are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
pretix GmbH / pretix
0 < 2026.4.6 2026.5.0 < 2026.5.4 2026.6.0 < 2026.6.1
References
Credits
dizconnectz