{"id":"CVE-2026-101267","published":"2026-09-29T13:17:49.457","lastModified":"2026-09-29T21:28:02.477","description":"A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://pretix.eu/about/en/blog/20260929-release-2026-7-1/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}