Impact
A missing authorization check in the quick setup view allows an attacker to execute privileged configuration changes on events they do not own. The attacker can create products, set quotas, configure bank transfer details, or link a Stripe account to the event. This flaw is an Authorization Bypass (CWE‑639) and directly undermines the integrity of event data.
Affected Systems
Pretix, by pretix GmbH, is affected by this vulnerability. The advisory does not specify which releases contain the issue, but the reference to release 2026‑6‑1 implies that newer versions address the flaw.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The attack requires the attacker to be authenticated but lack proper event permissions, and it relies on a timely request to the quick setup interface. Since the exploitation path is limited and the existing security controls reduce the likelihood of attack, the overall risk remains low but non‑negligible.
OpenCVE Enrichment