Junglewise Threat Intelligence

CVE-2026-5599: pretix Venueless improper isolation allows cross-world user deletion

CVE-2026-5599 · Severity: info · CVSS 7.3 · Published 2026-04-05

Technologies: Pretix Venueless. Vendors: Pretix.

Executive brief

Venueless, a platform for virtual events, contains a flaw that allows a user with administrative permissions in one event 'world' to delete user accounts in other completely separate event worlds. This could lead to significant disruption of service and unauthorized loss of attendee data across different organizations or events hosted on the same platform. An attacker only needs basic API access and standard user management permissions within their own event to perform this action.

Technical details

Venueless suffers from an improper isolation vulnerability (CWE-653) within its API. The root cause is a failure to properly scope user deletion requests to the specific 'world' (instance) the authenticated user belongs to. An attacker with 'manage users' permissions and API access can craft requests that target user identifiers belonging to other worlds. This allows for cross-tenant data modification and deletion. The vulnerability is exploitable over the network with low privileges (PR:L) but requires specific attack requirements (AT:P) related to identifying target user IDs. The issue has been addressed in commit 02b9cbe5.

Affected products

  • pretix Venueless < 02b9cbe5

Timeline

  • 2026-04-05: disclosed
  • 2026-04-05: advisory
  • 2026-04-05: patched

References

Related threats