CVE-2026-101267EPSS p13.7%

CVE-2026-101267CVE-2026-101267

Description

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.

Scoring

EPSS0.24% probability of exploitation · percentile 13.7% · 2026-10-05T12:00:23Z
Last modified2026-09-29
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.