CVE-2026-11764
LOW
3,6
Source: 655498c3-6ec5-4f0b-aea6-853b334d05a6
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
When creating an export of all reusable media, the secrets of connected
gift cards were included in the export even if the user creating the
export does not have permission to view gift cards. This is inconsistent
with the UI and API where only the first letters of the gift card
secret are shown. Therefore, it allows circumventing a permission
boundary.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0004
Percentile
0,1th
Updated
EPSS Score Trend (Last 5 Days)
280
Improper Handling of Insufficient Permissions or Privileges
DraftCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Other
Alter Execution Logic
Applicable Platforms
All platforms may be affected
https://pretix.eu/about/en/blog/20260609-release-2026-5-1/