Description
Our payment integration with GiroCheckout did not properly validate
payment status responses. An attacker could use a successful payment
status response from one payment and supply it to the system for a
different payment, gaining access to multiple valid tickets with only
one payment.
Published: 2026-07-28
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in a failure to properly validate payment status responses in the pretix-girosolution payment integration with GiroCheckout. An attacker can take a successful payment status from one transaction and supply it to the system for a different payment, thereby obtaining access to multiple valid tickets using only a single actual payment. This flaw allows an unauthorized user to claim tickets that were not legitimately purchased, compromising the integrity of the ticketing process.

Affected Systems

The affected product is pretix-girosolution supplied by pretix GmbH. No specific versions were listed, so all releases prior to the 2026-6-1 update are potentially vulnerable. Users should verify that their installation is not running the outdated component.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity, but the EPSS score of less than 1% shows that the probability of exploitation is currently very low. The vulnerability is not listed in CISA's KEV catalog, further suggesting that no widespread exploitation is documented. The likely attack vector involves manipulating or forging payment status responses sent to the ticketing system; an attacker would need access to the payment status flow or the ability to replay or alter transaction data. If successful, the attacker could obtain multiple tickets without having paid for each individually, undermining the revenue model and trust in the system.

Generated by OpenCVE AI on August 3, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest pretix-girosolution release (2026‑6‑1) which introduces proper payment status validation.
  • If an update is unavailable, consider disabling or restricting the GiroCheckout payment method until the fix is applied.
  • Review existing orders and issued tickets for suspicious activity and rerun any questionable transactions through a manual or separate validation process.

Generated by OpenCVE AI on August 3, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Pretix Gmbh
Pretix Gmbh pretix-girosolution
Vendors & Products Pretix Gmbh
Pretix Gmbh pretix-girosolution

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
Title Insufficient validation of payment status in pretix-girosolution
Weaknesses CWE-841
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Pretix Gmbh Pretix-girosolution
cve-icon MITRE

Status: PUBLISHED

Assigner: rami.io

Published:

Updated: 2026-07-28T12:36:18.719Z

Reserved: 2026-07-28T07:28:43.937Z

Link: CVE-2026-18029

cve-icon Vulnrichment

Updated: 2026-07-28T12:32:47.166Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T11:17:03.677

Modified: 2026-07-30T16:43:03.817

Link: CVE-2026-18029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses
  • CWE-841

    Improper Enforcement of Behavioral Workflow