Our payment integration with Oppwa-based payment methods did not
properly validate payment status responses. An attacker could use a
successful payment status response from one payment and supply it to the
system for a different payment, gaining access to multiple valid
tickets with only one payment.
properly validate payment status responses. An attacker could use a
successful payment status response from one payment and supply it to the
system for a different payment, gaining access to multiple valid
tickets with only one payment.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ |
|
History
Thu, 25 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. | |
| Title | Insufficient validation of payment status in pretix-oppwa | |
| Weaknesses | CWE-841 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2026-06-25T15:13:53.504Z
Reserved: 2026-06-24T16:01:13.668Z
Link: CVE-2026-13222
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T15:30:16Z
Weaknesses