pretix

Security release 2026.6.1 of pretix and one plugin

July 28, 2026

We have become aware of security issues in pretix due to external reports and internal discoveries.

We therefore just released versions 2026.6.1, 2026.5.4, and 2026.4.6 of pretix as well as updates for multiple plugins that fix these problems. It is strongly recommended that you update your installation as soon as possible.

If you are a customer of our pretix Hosted service, the vulnerabilities are already fixed for you and you do not need to take action.

#1: Missing authorization check in event quick setup view [LOW]

CVE ID: CVE-2026-57532

The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the given event. An attacker with limited permissions to the same event and organizer could use a well-timed request to create products, quotas, set bank transfer configuration, or connect a stripe account to an event they would otherwise only have read-only access to.

Severity rating: Since this can only be exploited by users within the organizers and only on events that are completely unconfigured and is likely to be noticed during actual configuration, we assess the severity to be low.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been reported to us by dizconnectz.

#2: Insufficient validation of payment status in pretix-girosolution [MEDIUM]

CVE ID: CVE-2026-18029

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

Severity rating: Since no data exposure is at risk and large-scale exploitation is likely to be noticed, we assess the severity as medium.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been discovered internally.

Fixed versions

We just released updates for the last three stable versions on PyPI that fix the problem. If you run a pretix installation older than 2026.3, please upgrade to a recent version now.

We have also published these fixed plugin versions:

  • pretix-girosolution 1.0.1 (Enterprise plugin)

The new docker images will appear on Docker Hub over the next few hours.

We strongly recommend that you always run the latest version of pretix, as every release contains useful and important bug fixes, even if they are not security related.

If you want to keep updated about bugfix and security releases, you should follow this blog closely. A RSS feed is available and we also announce every blogpost on Mastodon.

We take the security of our product very seriously and always go the extra mile to make sure you stay safe. As we are humans, security issues unfortunately still might occur from time to time. We do everything we can to find and fix them as timely as we can. If you notice any security problems or have any questions on this topic, please contact us in private at security@pretix.eu. We will always treat your message with the appropriate priority.

Raphael Michel

Raphael is the founder, CEO and technical lead for pretix. He is passionate about user-friendly, elegant software, and when he's not busy building software for conference organizers, he enjoys co-organizing con​fer​en​ces himself.

Read more blog posts

Any questions?
+49 6221 32177-50 Mo-Fr 09:00-17:00 Uhr