Impact
The vulnerability chain in pretix’s payment-integration plugins exploits improperly validated cryptographic signatures. Each plugin accepts session parameters parameters belong to that plugin’s namespace. An unrelated core feature that obfuscates Referer headers uses the same signing key and salt, allowing an attacker to forge signed payloads with arbitrary content. By injecting forged parameters into the payment module and using the admin impersonation endpoint, an attacker can switch a legitimate user’s session to any other user, gaining full backend access. Based on the description, it is inferred that an attacker can craft a URL embedding the forged parameters to trigger the exploit from a remote location.
Affected Systems
Affects the pretix event-management platform and all of its payment-integration plugins: pretix, pretix-bitpay, pretix-mollie, pretix-oppwa, pretix-payone, pretix-saferpay, pretix-secuconnect, pretix-sofort. No specific version list is included in the advisory, but the 2026-5-3 release addresses the weaknesses.
Risk and Exploitability
The flaw carries a CVSS score of 7.7, indicating high severity, while the EPSS score of <1% suggests a low current exploitation likelihood. It is not listed in the CISA KEV catalogue. Based on the description, it is inferred that the attack vector is remote and involves a crafted URL, requiring only access to a single event in the backend, making the exploitation path straightforward for a motivated adversary.
OpenCVE Enrichment