CVE-2026-101269Low· 2.3▾ SunlitThe mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUI…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 12.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101267Low· 2.7A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information
CVE-2026-101268Low· 1.7If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account
CVE-2026-101270Low· 2.1Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-101271Low· 2.1OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
CVE-2026-101266Low· 1.3A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.
CVE-2025-14881Lowpretix has Broken Access Control Allowing Cross-User File Access via UUID