Unrated severityNVD Advisory· Published Jul 28, 2026· Updated Jul 28, 2026
Insufficient validation of payment status in pretix-girosolution
CVE-2026-18029
Description
Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
Affected products
1Patches
Vulnerability mechanics
References
1- pretix.eu/about/en/blog/20260728-release-2026-6-1/mitrevendor-advisory
News mentions
0No linked articles in our index yet.