CVE-2026-101267

Status: Received

Description

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.

Published
September 29, 2026 1:17 PM
Last Modified
September 29, 2026 3:17 PM
Source
655498c3-6ec5-4f0b-aea6-853b334d05a6

Weaknesses (CWE)

CWE-862

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.