CVE-2026-13602
pretix pretix, pretix-mollie, pretix-oppwa
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay contain a code path that is intended for the transport of session parameters from a tab with isolated cookies (e.g. in the pretix widget) to a new tab. For this purpose, a set of session parameters is cryptographically signed and then passed to the new tab as a...
- CVSS
- 7.7
- EPSS
- 0.27% 19.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.02