pretix

Security release 2026.7.1 of pretix

Sept. 29, 2026

We have become aware of security issues in pretix due to external reports and internal discoveries.

We therefore just released versions 2026.7.1, 2026.6.2, and 2026.5.5 of pretix as well as updates for multiple plugins that fix these problems. It is strongly recommended that you update your installation as soon as possible.

If you are a customer of our pretix Hosted service, the vulnerabilities are already fixed for you and you do not need to take action.

#1: Checkout validation bypass [LOW]

CVE ID: CVE-2026-101266

A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.

Severity rating: Since the resulting orders have only visible violations and no data access is obtained, we assess the severity to be low.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been discovered internally.

#2: Revenue information leak [LOW]

CVE ID: CVE-2026-101267

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.

Severity rating: Since the vulnerability can only be exploited by users who do have access to the event in question and the leaked information is very limited and does not include personal information, we assess the severity to be low.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been discovered by Wenhao Wu of Southeast University.

#3: Customer session fixation [LOW]

CVE ID: CVE-2026-101268

If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.

Severity rating: Since the attack only works under very specific conditions and is usually quite visible to the victim, we assess the severity to be low.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been discovered internally.

#4: Incorrect session validation for API-uploaded files [LOW]

CVE ID: CVE-2026-101269

The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.

Severity rating: Since the attack requires knowledge of a UUID, which is not guessable, we assess the severity to be low.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been discovered by Wenhao Wu of Southeast University.

#5: HTML injection [LOW]

CVE ID: CVE-2026-101270

Malicious HTML content could be injected into the help texts of various fields with organizer permissions.

Severity rating: Since the XSS occurs on pages with a strong Content-Security-Policy, we assess the severity as low.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been discovered internally.

#6: OAuth credentials not disabled when application is disabled [LOW]

CVE ID: CVE-2026-101271

OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.

Severity rating: Since the tokens are only valid for their remaining lifetime and cannot be renewed, we assess the severity as low.

Affected versions: All currently supported versions (except the fixed versions listed below) are affected.

This issue has been discovered internally.

Denial-of-Service opportunities fixed

We fixed multiple inefficient code paths discovered during our search for security issues that could potentially be abused for denial-of-service attacks. We do not assign CVEs to these kinds of issues and do not usually backport them, but have included them in this security release.

Fixed versions

We just released updates for the last three stable versions on PyPI that fix the problem. If you run a pretix installation older than 2026.5, please upgrade to a recent version now.

The new docker images will appear on Docker Hub over the next few hours.

We strongly recommend that you always run the latest version of pretix, as every release contains useful and important bug fixes, even if they are not security related.

If you want to keep updated about bugfix and security releases, you should follow this blog closely. A RSS feed is available and we also announce every blogpost on Mastodon.

We take the security of our product very seriously and always go the extra mile to make sure you stay safe. As we are humans, security issues unfortunately still might occur from time to time. We do everything we can to find and fix them as timely as we can. If you notice any security problems or have any questions on this topic, please contact us in private at security@pretix.eu. We will always treat your message with the appropriate priority.

Raphael Michel

Raphael is the founder, CEO and technical lead for pretix. He is passionate about user-friendly, elegant software, and when he's not busy building software for conference organizers, he enjoys co-organizing con​fer​en​ces himself.

Read more blog posts

Any questions?
+49 6221 32177-50 Mo-Fr 09:00-17:00 Uhr