CVE-2026-101271
LOW
2,1
Source: 655498c3-6ec5-4f0b-aea6-853b334d05a6
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
https://pretix.eu/about/en/blog/20260929-release-2026-7-1/