CVE-2026-72690
Attendize Attendize - Cross-Tenant Authorization Bypass
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events via the POST /event/{event_id}/question/create endpoint. The postCreateEventQuestion method loads the target event without the tenant-isolation scope, enabling cross-tenant writes; the injected question cannot be removed by the victim because the victim's account-scoped delete path cannot resolve a question owned by another tenant.
| CWE | CWE-639 |
| Vendor | attendize |
| Product | attendize |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for attendize attendize
Be the first to know when new medium vulnerabilities affecting attendize attendize are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
Low
Affected Versions
Attendize / Attendize
0 โค 9289acb
Credits
Bobur Abdugafforov (Mahadsec)