PT-2026-54631 · Pretix+1 · Pretix-Saferpay+8
CVE-2026-13602
·
Published
2026-07-01
·
Updated
2026-07-09
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U |
Name of the Vulnerable Software and Affected Versions
pretix versions prior to 2026.5.3
Description
A chain of weaknesses allows an attacker to impersonate any user in the backend and access any data. The issue stems from payment integration plugins (Stripe, pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay) that fail to validate session parameters beyond a cryptographic signature. A separate feature used to generate redirect links to obfuscate Referer headers uses the same key and salt for signatures as the payment plugins. An attacker with access to at least one event in the backend can trick the system into signing arbitrary content, which can then be injected into the payment provider feature to modify session parameters. Finally, an administrative feature designed to allow users to act on behalf of others for debugging can be abused to switch the attacker's session to any user in the system by guessing a valid user ID.
Recommendations
Update to version 2026.5.3.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stripe
Pretix
Pretix-Bitpay
Pretix-Mollie
Pretix-Oppwa
Pretix-Payone
Pretix-Saferpay
Pretix-Secuconnect
Pretix-Sofort