Data exposed without proper permission
Summary
| CVE | CVE-2026-11764 |
|---|---|
| State | PUBLISHED |
| Assigner | rami.io |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-09 13:16:35 UTC |
| Updated | 2026-06-09 13:57:49 UTC |
| Description | When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the export does not have permission to view gift cards. This is inconsistent with the UI and API where only the first letters of the gift card secret are shown. Therefore, it allows circumventing a permission boundary. |
Risk And Classification
Primary CVSS: v4.0 3.6 LOW from 655498c3-6ec5-4f0b-aea6-853b334d05a6
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002290000 probability, percentile 0.134970000 (date 2026-06-16)
Problem Types: CWE-280 | CWE-280 CWE-280 Improper handling of insufficient permissions or privileges
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 655498c3-6ec5-4f0b-aea6-853b334d05a6 | Secondary | 3.6 | LOW | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/C... |
| 4.0 | CNA | CVSS | 3.6 | LOW | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
HighSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| pretix.eu/about/en/blog/20260609-release-2026-5-1 | 655498c3-6ec5-4f0b-aea6-853b334d05a6 | pretix.eu | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Mr. JDH (en)
There are currently no legacy QID mappings associated with this CVE.