An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events via the POST /event/{event_id}/question/create endpoint. The postCreateEventQuestion method loads the target event without the tenant-isolation scope, enabling cross-tenant writes; the injected question cannot be removed by the victim because the victim's account-scoped delete path cannot resolve a question owned by another tenant.
References
| Link | Resource |
|---|---|
| https://github.com/Attendize/Attendize |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 13:20
Updated : 2026-08-26 17:36
NVD link : CVE-2026-72690
Mitre link : CVE-2026-72690
CVE.ORG link : CVE-2026-72690
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
