CVE-2026-13350

LOW

Pretix Venueless < 0a35457f - Authorization Bypass Through User-Controlled Key

Title source: rule
STIX 2.1

Description

Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.

Scores

CVSS v4 2.3
EPSS 0.0017
EPSS Percentile 6.7%
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
pretix/Venueless 0.0.0 - 0a35457f
Published Jun 25, 2026
Tracked Since Jun 25, 2026