PT-2026-47750 · Git+1 · Pretix

·

CVE-2026-11764

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v4.0

3.6

Low

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An issue exists where exporting all reusable media includes the secrets of connected gift cards, regardless of whether the user performing the export has the required permissions to view them. This behavior bypasses established permission boundaries and contradicts the security controls implemented in the UI and API, which only display the initial characters of the gift card secret.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11764

Affected Products

Pretix