CVE-2026-101267Low· 2.7▾ SunlitA missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101268Low· 1.7If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account
CVE-2026-101269Low· 2.3The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users
CVE-2026-101270Low· 2.1Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-101271Low· 2.1OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
CVE-2026-101266Low· 1.3A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.
CVE-2025-14881Lowpretix has Broken Access Control Allowing Cross-User File Access via UUID