CVE-2026-101271

Published: Set 29, 2026 Last Modified: Set 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,1
Source: 655498c3-6ec5-4f0b-aea6-853b334d05a6
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.

https://pretix.eu/about/en/blog/20260929-release-2026-7-1/