CVE-2026-101267: Revenue information leak
Published Sep 29, 2026
·Updated
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
Event History
Sep 29, 2026
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
Description
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who could exploit this issue?
Low-privileged users who had access to an event but did not have permission to access that event's orders could extract the attendee count and total revenue.
2
What information could be exposed?
The exposed information included the number of attendees for the event and the event's total revenue.