Executive brief
pretix is a popular open-source ticketing and event management platform. A security flaw in a recently introduced API endpoint allows users with access to one event to view ticket check-in data for all other events managed by the same organizer. While this data does not directly identify individuals, it exposes sensitive operational information such as ticket scan times and success rates across an organizer's entire portfolio.
Technical details
An improper isolation vulnerability (CWE-653) exists in a new API endpoint introduced in pretix 2025. The endpoint, intended to return check-in events for a specific event, fails to properly scope results, instead returning all check-in records belonging to the respective organizer. An authenticated API consumer can exploit this to retrieve data including scan timestamps, device IDs, and internal ticket position IDs for events they should not have access to. The issue is resolved in versions 2026.1.2, 2026.2.1, and 2026.3.1.
Affected products
- rami.io pretix 2025.10.0 to 2026.1.1, 2026.2.0, 2026.3.0
Timeline
- 2026-04-08: advisory: Vendor advisory and blog post published
- 2026-04-08: patched: Fixed versions 2026.1.2, 2026.2.1, and 2026.3.1 released