LOW 2.7 NVD
CVE-2026-101267
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. T
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
References
This low severity vulnerability with a CVSS score of 2.7 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.