CVE-2026-13602Patch

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay contain a code path that is intended for the transport of session parameters from a tab with isolated cookies (e.g. in the pretix widget) to a new tab. For this purpose, a set of session parameters is cryptographically signed and then passed to the new tab as a URL parameter. The plugins perform no further validation of the session parameters, other than the cryptographic signature being valid. This is fixed with the releases issued today by strictly validating that no session parameters outside of the scope of the respective plugin may be set. * An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer headers for outgoing links to prevent leakage of secrets in URLs. This redirect page also requires cryptographically signed parameters. Unfortunately, it uses the same key and salt for the signature as the previously mentioned feature in the payment integration plugins. A motivated attacker with access to at least one event in the backend can trick the system into cryptographically signing arbitrary content using specially crafted links. In combination with the previous issue, the attacker could use this to set and modify arbitrary parameters on their user session by injecting the signed parameters into the feature of the payment providers. This is fixed with the releases issued today by using different salts for the signature for each plugin and feature. * A third, unrelated feature in the core system is used for admin users to act on behalf of another user, mostly for debugging purposes. With being able to insert arbitrary parameters into a session, an attacker can abuse this feature to change their session from their actual user to any user in the system by guessing a valid user ID. This is fixed with the release today by requiring unguessable information to be contained in the session of the user to switch to.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-323

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 107-0807-09
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 CVE-2026-13602: New pretix vulnerabilities include a critical session takeover issue, alongside an SSRF flaw that could expose API keys. Update to v2026.5.3. #CyberSecurity #CVE #Pretix #SSRF #ThreatWire

    Post summary

    The announcement highlights CVE-2026-13602 affecting Pretix with session takeover and SSRF vulnerabilities, and advises upgrading to v2026.5.3. No active exploitation or proof‑of‑concept details are provided.

    0001062
    66 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    New pretix vulnerabilities include a critical session takeover chain (CVE-2026-13602) and an SSRF API key leak. Update to 2026.5.3 now. #pretix #SessionTakeover #SSRF #CyberSecurity #CVE202613602 #CVE202613603 http://securityonline.info/pretix-vulnerabilities/

    Post summary

    The post announces new pretix vulnerabilities (CVE‑2026‑13602 and CVE‑2026‑13603) and directs users to patch with release 2026.5.3.

    00000444
    12.5K followersView on X

Explore more