---
id: CVE-2026-101269
title: >-
  The mechanism binding API-uploaded files to the uploader's authentication
  method is not working correctly and the same session token is used for all
  token-based API users
summary: >-
  The mechanism binding API-uploaded files to the uploader's authentication
  method is not working correctly and the same session token is used for all
  token-based API users. Since API-uploaded files are refered to by randomly
  generated UUI…
severity: low
cvss: 2.3
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'
vendor: pretix
product: pretix
affected:
  - pretix >= 0.0 < 2026.5.5
  - pretix >= 2026.6.0 < 2026.6.2
  - pretix >= 2026.7.0 < 2026.7.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T13:17:49.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101269'
references:
  - url: 'https://pretix.eu/about/en/blog/20260929-release-2026-7-1/'
    label: 655498c3-6ec5-4f0b-aea6-853b334d05a6
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T12:33:37.303Z'
---

## Overview

The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
