---
id: CVE-2026-101268
title: >-
  If an attacker is able to convince a victim on a specially crafted link, the
  victim is logged in to the attacker's customer account
summary: >-
  If an attacker is able to convince a victim on a specially crafted link, the
  victim is logged in to the attacker's customer account. If the victim does not
  notice this, this might lead to their order details being stored into the
  attacke…
severity: low
cvss: 1.7
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U'
vendor: pretix
product: pretix
affected:
  - pretix >= 0.0 < 2026.5.5
  - pretix >= 2026.6.0 < 2026.6.2
  - pretix >= 2026.7.0 < 2026.7.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T13:17:49.597'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101268'
references:
  - url: 'https://pretix.eu/about/en/blog/20260929-release-2026-7-1/'
    label: 655498c3-6ec5-4f0b-aea6-853b334d05a6
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T12:33:37.304Z'
---

## Overview

If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
