CVE-2026-18028

The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the given event. An attacker could use a well-timed request to create products, quotas, set bank transfer configuration, or connect a stripe account to an event they do not have access to.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-28 11:17

Updated : 2026-07-30 16:43


NVD link : CVE-2026-18028

Mitre link : CVE-2026-18028

CVE.ORG link : CVE-2026-18028


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key