---
id: CVE-2026-101271
title: >-
  OAuth credentials (access tokens) are valid for the entirety of their
  lifetime, even if the application (OAuth client) they are bound to is manually
  disabled.
summary: >-
  OAuth credentials (access tokens) are valid for the entirety of their
  lifetime, even if the application (OAuth client) they are bound to is manually
  disabled.
severity: low
cvss: 2.1
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'
vendor: pretix
product: pretix
affected:
  - pretix >= 0.0 < 2026.5.5
  - pretix >= 2026.6.0 < 2026.6.2
  - pretix >= 2026.7.0 < 2026.7.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T13:17:49.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101271'
references:
  - url: 'https://pretix.eu/about/en/blog/20260929-release-2026-7-1/'
    label: 655498c3-6ec5-4f0b-aea6-853b334d05a6
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-29T12:33:37.300Z'
---

## Overview

OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
