Junglewise Threat Intelligence

CVE-2026-13350: Pretix Venueless authorization bypass in room creation

CVE-2026-13350 · Severity: info · CVSS 2.3 · Published 2026-06-25

Technologies: Pretix / Rami.Io Venueless.

Executive brief

Venueless, a virtual event platform, contains a flaw in how it validates user permissions during the creation of virtual rooms. An authorized user could exploit this to create specific types of rooms that they should not have the authority to manage. This could lead to unauthorized use of platform features or organizational inconsistencies during a virtual event.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Venueless due to incorrect permission validation during the room creation process. A remote attacker with low-level authenticated privileges can bypass intended restrictions to create room types that should be restricted to higher-privileged roles. The attack requires specific conditions (Attack Requirements: Present) and has high complexity, but it allows for unauthorized modification of system state (Integrity: Low). The issue is addressed in git commit 040ae040.

Affected products

  • pretix / rami.io Venueless < 040ae040 (git)

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory
  • 2026-06-25: patched

References