Junglewise Threat Intelligence

CVE-2026-11764: rami.io pretix improper handling of permissions in reusable media export

CVE-2026-11764 · Severity: info · CVSS 3.6 · Published 2026-06-09

Technologies: Rami.Io Pretix. Vendors: Rami.Io.

Executive brief

pretix is a ticketing and event management platform. A security flaw allowed authorized staff members to export sensitive gift card secrets even if they did not have the specific permissions required to view that data. This could lead to unauthorized access to gift card funds by internal users who should only have limited administrative access.

Technical details

An improper handling of insufficient permissions (CWE-280) exists in the 'reusable media' export functionality of pretix. While the user interface and API correctly redact gift card secrets for users without specific gift card permissions, the bulk export feature included the full secrets in its output. An attacker must already have high-level administrative privileges (specifically the ability to export reusable media) to exploit this. The vulnerability allows for a bypass of intended permission boundaries, potentially exposing sensitive financial data to unauthorized internal staff. The issue is addressed in versions 2026.5.1, 2026.4.3, and 2026.3.3.

Affected products

  • rami.io pretix 2024.1.0 to 2026.5.0

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: patched
  • 2026-06-09: advisory

References

Related threats