Description
Our payment integration with Mollie did not properly validate payment
status responses. An attacker could use a successful payment status
response from one payment and supply it to the system for a different
payment, gaining access to multiple valid tickets with only one payment.
status responses. An attacker could use a successful payment status
response from one payment and supply it to the system for a different
payment, gaining access to multiple valid tickets with only one payment.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ |
|
History
Thu, 25 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. | |
| Title | Insufficient validation of payment status in pretix-mollie | |
| Weaknesses | CWE-841 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2026-06-25T15:13:30.071Z
Reserved: 2026-06-24T15:59:32.629Z
Link: CVE-2026-57536
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-841
Improper Enforcement of Behavioral Workflow