CVE-2026-101271: fallo de gravedad baja en pretix
OAuth credentials not disabled when application is disabled
Publicada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 2.1epss 0.2%
probabilidad de explotación
0.2%top 94% de las CVE
explotación observada
noninguna fuente lo reporta
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
pretix · pretixCVEs relacionadas — pretix
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-13225MEDIUMStored XSS in ticket confirmation pageEPSS 0.4%CVE-2026-57532HIGHCVE-2026-57532EPSS 0.4%CVE-2026-57535LOWCVE-2026-57535EPSS 0.4%CVE-2026-13602HIGHSession takeover vulnerabilityEPSS 0.4%CVE-2026-9712LOWInsecure direct object referenceEPSS 0.4%CVE-2024-8113HIGHStored XSS in Placeholder Samples in Mail PreviewEPSS 0.3%