PT-2026-30436 · Pretix · Venueless
Pratik Karan
·
Published
2026-04-05
·
Updated
2026-04-05
·
CVE-2026-5599
CVSS v4.0
7.3
High
| AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
A user with API access and "manage users" permission in any venueless
world is able to trigger deletion of user accounts in other worlds.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Venueless