---
id: CVE-2026-101267
title: >-
  A missing permission check allowed low-privileged users with access to an
  event but without access to the event's orders to extract some specific
  information
summary: >-
  A missing permission check allowed low-privileged users with access to an
  event but without access to the event's orders to extract some specific
  information. This information includes the number of attendees and the total
  revenue.
severity: low
cvss: 2.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U'
vendor: pretix
product: pretix
affected:
  - pretix >= 0.0 < 2026.5.5
  - pretix >= 2026.6.0 < 2026.6.2
  - pretix >= 2026.7.0 < 2026.7.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T13:17:49.457'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101267'
references:
  - url: 'https://pretix.eu/about/en/blog/20260929-release-2026-7-1/'
    label: 655498c3-6ec5-4f0b-aea6-853b334d05a6
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T12:33:37.304Z'
---

## Overview

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
