Junglewise Threat Intelligence

CVE-2026-60118: Hi.Events missing authorization for hidden tickets in order creation

CVE-2026-60118 · Severity: medium · CVSS 5.3 · Published 2026-07-14

Technologies: HiEventsDev Hi.Events. Vendors: HiEventsDev.

Executive brief

Hi.Events, an open-source event management and ticketing platform, contains a flaw that allows unauthorized users to purchase tickets that were intentionally hidden from the public. By guessing or predicting ticket identification numbers, an attacker can buy VIP, invite-only, or discounted tickets that should not be available for general sale. This could lead to financial loss for event organizers and unauthorized access to restricted event tiers.

Technical details

A missing server-side visibility enforcement vulnerability exists in the order creation endpoint of Hi.Events. The application fails to verify if a product or price ID submitted in a POST request to `/api/public/events/{id}/order` is marked as 'hidden' in the database. Because ticket and price IDs are sequential integers, an unauthenticated attacker can enumerate these IDs to identify and purchase restricted items such as VIP or discounted tickets. The vulnerability is addressed in version v1.11.0-beta by implementing server-side checks to reject hidden products during the public checkout flow.

Affected products

  • HiEventsDev Hi.Events through v1.10.0-beta

Timeline

  • 2026-07-07: patched: Fix merged in pull request #1259
  • 2026-07-09: patched: Version v1.11.0-beta released
  • 2026-07-13: advisory: GitHub Security Advisory GHSA-2h54-cprv-vj74 published
  • 2026-07-14: disclosed: CVE-2026-60118 published to NVD

References

Related threats