CVE-2026-57960

MEDIUM

Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id

Title source: cna
STIX 2.1

Description

Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET /api/public/check-in-lists/{short_id}/attendees to read attendee data and create or delete check-in records without authentication.

References (3)

Core 3
Core References
Issue Tracking issue-tracking
Pull Request
https://github.com/HiEventsDev/Hi.Events/pull/1229
Technical Description issue-tracking
Researcher Disclosure
https://github.com/HiEventsDev/Hi.Events/issues/1224

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-359
Status published
Products (1)
HiEventsDev/Hi.Events < 1.9.0
Published Jun 29, 2026
Tracked Since Jun 29, 2026