OVERVIEW CVE-2026-5600 is an authorization bypass vulnerability affecting pretix 2025, specifically a newly introduced API endpoint designed to retrieve check-in events for a specific event. Due to improper access controls, the endpoint returns all check-in events associated with the organizer rather than limiting results to the requested event, allowing unauthorized API consumers to access ticket scan data across multiple events they should not have permissions to view. The exposed records contain sensitive check-in information including scan timestamps, results, ticket IDs, and device information. SEVERITY The vulnerability has a FAUCET Risk Score of 41.0/100, indicating moderate concern. The attack vector is network-based through the API endpoint, and exploitation requires minimal complexity as an attacker need only possess valid API credentials for any event under the target organizer. The impact is primarily informational disclosure, as attackers gain unauthorized visibility into ticket scanning activity, timing patterns, and ticket matching data across the organization. While the exposed ticket position IDs cannot be easily correlated to individual attendees without additional data, the broader operational and competitive intelligence gained from comprehensive check-in patterns represents a meaningful privacy and business confidentiality risk. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is currently available. The EPSS score of 0.00016 indicates very low predicted probability of exploitation, suggesting minimal community attention or attacker interest at present. Organizations using pretix 2025 should prioritize patching, but the threat level remains low based on current exploit activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2025.10.0, < 2026.1.2CPE matchmatch criteria | cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:* | ||
>= 2026.2.0, < 2026.2.1CPE matchmatch criteria | cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:* | ||
>= 2026.3.0, < 2026.3.1CPE matchmatch criteria | cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.