Junglewise Threat Intelligence

CVE-2026-18029: pretix pretix-girosolution improper payment status validation

CVE-2026-18029 · Severity: info · CVSS 6.3 · Published 2026-07-28

Executive brief

A vulnerability exists in the GiroCheckout payment integration for the pretix ticketing system. The software fails to properly verify payment status responses, which could allow an attacker to reuse a single successful payment confirmation to obtain multiple valid tickets. This could lead to financial loss for event organizers as users could bypass paying for additional tickets.

Technical details

The vulnerability is classified as an improper enforcement of behavioral workflow (CWE-841) within the pretix-girosolution plugin. The root cause is insufficient validation of payment status responses returned by the GiroCheckout integration. A remote attacker can capture a valid payment status response from one transaction and replay or supply it to the system for a different, unpaid transaction. This allows the attacker to gain access to multiple valid tickets while only paying for one. The issue is fixed in pretix-girosolution version 1.0.1.

Affected products

  • pretix GmbH pretix-girosolution < 1.0.1

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: patched: Fixed in pretix-girosolution 1.0.1

References