Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5600

20
FAUCET Score

OVERVIEW CVE-2026-5600 is an authorization bypass vulnerability affecting pretix 2025, specifically a newly introduced API endpoint designed to retrieve check-in events for a specific event. Due to improper access controls, the endpoint returns all check-in events associated with the organizer rather than limiting results to the requested event, allowing unauthorized API consumers to access ticket scan data across multiple events they should not have permissions to view. The exposed records contain sensitive check-in information including scan timestamps, results, ticket IDs, and device information. SEVERITY The vulnerability has a FAUCET Risk Score of 41.0/100, indicating moderate concern. The attack vector is network-based through the API endpoint, and exploitation requires minimal complexity as an attacker need only possess valid API credentials for any event under the target organizer. The impact is primarily informational disclosure, as attackers gain unauthorized visibility into ticket scanning activity, timing patterns, and ticket matching data across the organization. While the exposed ticket position IDs cannot be easily correlated to individual attendees without additional data, the broader operational and competitive intelligence gained from comprehensive check-in patterns represents a meaningful privacy and business confidentiality risk. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is currently available. The EPSS score of 0.00016 indicates very low predicted probability of exploitation, suggesting minimal community attention or attacker interest at present. Organizations using pretix 2025 should prioritize patching, but the threat level remains low based on current exploit activity.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2025.10.0, < 2026.1.2CPE matchmatch criteria
cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:*
>= 2026.2.0, < 2026.2.1CPE matchmatch criteria
cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:*
>= 2026.3.0, < 2026.3.1CPE matchmatch criteria
cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 21st percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

pippatch availablevia ghsa
Product: pretixFixed in: 2026.3.1
pippatch availablevia ghsa
Product: pretixFixed in: 2026.2.1
pippatch availablevia ghsa
Product: pretixFixed in: 2026.1.2

Vendor Advisories (1)

pipGHSA-wr8q-c73g-m7gpmedium

pretix: API leaks check-in data between events of the same organizer

Apr 8, 2026

References

pretix.eu / about/en/blog/20260408-release-2026-3-1
Vendor Advisory