Our payment integration with GiroCheckout did not properly validate
payment status responses. An attacker could use a successful payment
status response from one payment and supply it to the system for a
different payment, gaining access to multiple valid tickets with only
one payment.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Pretix Gmbh
Pretix Gmbh pretix-girosolution
Vendors & Products Pretix Gmbh
Pretix Gmbh pretix-girosolution

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
Title Insufficient validation of payment status in pretix-girosolution
Weaknesses CWE-841
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: rami.io

Published:

Updated: 2026-07-28T12:36:18.719Z

Reserved: 2026-07-28T07:28:43.937Z

Link: CVE-2026-18029

cve-icon Vulnrichment

Updated: 2026-07-28T12:32:47.166Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T11:17:03.677

Modified: 2026-07-30T16:43:03.817

Link: CVE-2026-18029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses