CVE-2026-57959

MEDIUM

Hi.Events 1.9.0 - Promo Code Max-Usage Bypass via Asynchronous Job Race Condition

Title source: cna
STIX 2.1

Description

Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo codes unlimited times. Attackers can sequentially reserve multiple orders with the same restricted promo code, each reading order_usage_count=0 and passing validation, then complete them all at discounted prices without concurrent requests.

References (2)

Core 2
Core References
Issue Tracking issue-tracking
Researcher Disclosure
https://github.com/HiEventsDev/Hi.Events/issues/1223

Scores

CVSS v3 5.9
EPSS 0.0019
EPSS Percentile 9.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (1)
HiEventsDev/Hi.Events < 1.9.0
Published Jun 29, 2026
Tracked Since Jun 29, 2026