PT-2026-54631 · Pretix+1 · Pretix-Saferpay+8

CVE-2026-13602

·

Published

2026-07-01

·

Updated

2026-07-09

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U
Name of the Vulnerable Software and Affected Versions pretix versions prior to 2026.5.3
Description A chain of weaknesses allows an attacker to impersonate any user in the backend and access any data. The issue stems from payment integration plugins (Stripe, pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay) that fail to validate session parameters beyond a cryptographic signature. A separate feature used to generate redirect links to obfuscate Referer headers uses the same key and salt for signatures as the payment plugins. An attacker with access to at least one event in the backend can trick the system into signing arbitrary content, which can then be injected into the payment provider feature to modify session parameters. Finally, an administrative feature designed to allow users to act on behalf of others for debugging can be abused to switch the attacker's session to any user in the system by guessing a valid user ID.
Recommendations Update to version 2026.5.3.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13602

Affected Products

Stripe
Pretix
Pretix-Bitpay
Pretix-Mollie
Pretix-Oppwa
Pretix-Payone
Pretix-Saferpay
Pretix-Secuconnect
Pretix-Sofort