๐Ÿ” CVE Alert

CVE-2026-5600

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people.

CWE CWE-653
Vendor pretix
Product pretix
Published Apr 8, 2026
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for pretix pretix

Be the first to know when new unknown vulnerabilities affecting pretix pretix are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

pretix / pretix
2025.10.0 < 2026.1.2 2026.2.0 < 2026.2.1 2026.3.0 < 2026.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
pretix.eu: https://pretix.eu/about/en/blog/20260408-release-2026-3-1/

Credits

Pratik Karan