CVE 3.6 LOW

Data exposed without proper permission_CVE-2026-11764

3.6 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U

Description

When creating an export of all reusable media, the secrets of connected
gift cards were included in the export even if the user creating the
export does not have permission to view gift cards. This is inconsistent
with the UI and API where only the first letters of the gift card
secret are shown. Therefore, it allows circumventing a permission
boundary.

Basic Information

ID CVE-2026-11764
Source rami.io
Published Jun 9, 2026 at 11:54

Affected Product

Vendor pretix
Product pretix
Version 2024.1.0
Affected Versions pretix pretix 2024.1.0
pretix pretix 2026.3.0
pretix pretix 2026.4.0
pretix pretix 2026.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.