CVE-2026-101267

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.

  • Published Sep 29, 2026
  • CVSS 2.7 low
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-101267 at the National Vulnerability Database