CVE-2026-101267
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
- Published Sep 29, 2026
- CVSS 2.7 low
- 0.2% chance of exploitation in the next 30 days (EPSS)