Junglewise Threat Intelligence

CVE-2026-13222: pretix-oppwa improper validation of payment status

CVE-2026-13222 · Severity: info · CVSS 6.3 · Published 2026-06-25

Vendors: Pretix.

Executive brief

A vulnerability in the Oppwa payment integration for the pretix ticketing system allows users to bypass payment requirements. By reusing a valid payment confirmation from one transaction for a different order, an attacker can obtain multiple tickets while only paying for one. This could lead to financial loss for event organizers and unauthorized access to events.

Technical details

The pretix-oppwa plugin (the Oppwa-based payment integration for pretix) contains a logic flaw in its payment status validation. The component fails to sufficiently verify that a payment status response corresponds to the specific transaction being processed. An attacker can exploit this by capturing a successful payment status response from one transaction and replaying or supplying it to the system for a different order. This results in the system marking multiple orders as paid based on a single actual payment. The vulnerability is fixed in version 1.4.3.

Affected products

  • pretix pretix-oppwa < 1.4.3

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory
  • 2026-06-25: patched

References

Related threats