CVE-2026-50165: alf.io has Improper Access Control for Organization Owners that Exposes System Secrets

Published Sep 9, 2026
·
Updated

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. An Improper Access Control issue in versions prior to 2.0-M5-2605 allows an organization owner to read system-level configuration secrets through organization/event scoped "single configuration" endpoints. The affected endpoints require organization or event ownership, but they accept an arbitrary configuration key and then return the first matching value from a lookup that includes system-level configuration. As a result, an organization owner can retrieve secrets intended to be administrator-only, including the system API key when it is configured. Version 2.0-M5-2605 fixes the issue.

Affected Software

1 affected component
alf.io alf.io<2.0-M5-2605

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade alf.io to a version that resolves this vulnerability.

    Fixed in 2.0-M5-2605

Event History

Sep 9, 2026
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated organization owner, or an owner of an event within an organization, can access the affected organization- or event-scoped single-configuration endpoints. No system administrator role is required.

2

What information could be exposed?

The endpoints can return system-level configuration values when supplied with an arbitrary configuration key. This includes the system API key if it is configured.

3

Which deployments are affected?

alf.io versions before 2.0-M5-2605 are affected. Exposure depends on an organization or event owner being able to query a key corresponding to a system-level secret.

4

How can I determine whether I may already be exposed?

Review whether organization or event owners have used the single-configuration endpoints to request system-level configuration keys, particularly the system API key. The provided information does not indicate whether such access is logged or otherwise detectable.

5

What is the remediation?

Upgrade alf.io to version 2.0-M5-2605. If the system API key may have been exposed, treat it as compromised and rotate it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203