CVE-2026-101271

Source
https://cve.org/CVERecord?id=CVE-2026-101271
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101271.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101271
Published
2026-09-29T12:03:44Z
Modified
2026-10-03T11:45:25Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
OAuth credentials not disabled when application is disabled
Details

OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.

Database specific
{
    "cna_assigner": "rami.io",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101271.json"
}
References

Affected packages

Git / github.com/pretix/pretix

Affected ranges

Type
GIT
Repo
https://github.com/pretix/pretix
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.0"
        },
        {
            "fixed": "2026.5.5"
        },
        {
            "introduced": "2026.6.0"
        },
        {
            "fixed": "2026.6.2"
        },
        {
            "introduced": "2026.7.0"
        },
        {
            "fixed": "2026.7.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0
1.0.0b1
1.0.0b2
Other
s
v1.*
v1.1.0
v1.10.0
v1.11.0
v1.12.0
v1.13.0
v1.14.0
v1.15.0
v1.16.0
v1.17.0
v1.2.0
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.8.0
v1.9.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2023.*
v2023.10.0
v2023.6.0
v2023.7.0
v2023.8.0
v2023.9.0
v2024.*
v2024.1.0
v2024.10.0
v2024.11.0
v2024.2.0
v2024.3.0
v2024.4.0
v2024.5.0
v2024.6.0
v2024.7.0
v2024.8.0
v2024.9.0
v2025.*
v2025.1.0
v2025.10.0
v2025.2.0
v2025.3.0
v2025.4.0
v2025.5.0
v2025.6.0
v2025.7.0
v2025.8.0
v2025.9.0
v2026.*
v2026.1.0
v2026.2.0
v2026.3.0
v2026.4.0
v2026.5.0
v2026.5.1
v2026.5.2
v2026.5.3
v2026.5.4
v2026.6.0
v2026.6.1
v2026.7.0
v3.*
v3.0.0
v3.1.0
v3.10.0
v3.11.0
v3.13.0
v3.14.0
v3.15.0
v3.16.0
v3.17.0
v3.18.0
v3.2.0
v3.3.0
v3.4.0
v3.5.0
v3.6.0
v3.7.0
v3.8.0
v3.9.0
v4.*
v4.0.0
v4.1.0
v4.10.0
v4.11.0
v4.13.0
v4.14.0
v4.15.0
v4.16.0
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.20.0
v4.3.0
v4.5.0
v4.6.0
v4.7.0
v4.8.0
v4.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101271.json"