Junglewise Threat Intelligence

CVE-2026-50165: alf.io improper access control in configuration endpoints

CVE-2026-50165 · Severity: info · Published 2026-09-09

Technologies: Alf.Io. Vendors: Alf.Io.

Executive brief

alf.io is an open-source ticket reservation system used by conferences and events to manage registrations. An access control flaw allows organization owners to retrieve sensitive system-level secrets—such as API keys, email service credentials, and payment processor tokens—that should only be accessible to administrators. An attacker with organization ownership can exploit this to gain unauthorized administrative API access across the entire system.

Technical details

The vulnerability is an improper access control flaw (CWE-284) in organization/event-scoped configuration endpoints that accept an arbitrary configuration key parameter. Although the endpoints correctly require organization or event ownership, they perform a lookup that includes system-level configuration alongside organization-level configuration and return the first matching key—allowing the lookup to escape the intended scope. An authenticated organization owner can abuse this by requesting system secrets like SYSTEM_API_KEY, SMTP_PASSWORD, or payment processor credentials through endpoints like /admin/api/configuration/organizations/{organizationId}/single/{KEY}. If SYSTEM_API_KEY is exposed, the attacker can chain this into further API abuse to mint API keys for other organizations or perform administrative operations. The fix was released in version 2.0-M5-2606, which restricts the configuration lookup to organization-scoped values only.

Affected products

  • alf.io alf.io <2.0-M5-2606

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: patched: Version 2.0-M5-2606 released

References

Related threats