CVE-2026-57959
MEDIUMHi.Events 1.9.0 - Promo Code Max-Usage Bypass via Asynchronous Job Race Condition
Title source: cnaDescription
Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo codes unlimited times. Attackers can sequentially reserve multiple orders with the same restricted promo code, each reading order_usage_count=0 and passing validation, then complete them all at discounted prices without concurrent requests.
References (2)
Core 2
Core References
Issue Tracking issue-tracking
Researcher Disclosure
https://github.com/HiEventsDev/Hi.Events/issues/1223
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/hi-events-promo-code-max-usage-bypass-via-asynchronous-job-race-condition
Scores
CVSS v3
5.9
EPSS
0.0019
EPSS Percentile
9.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-367
Status
published
Products (1)
HiEventsDev/Hi.Events
< 1.9.0
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026