
A serious security flaw (CVE-2026-41241) in pretalx — open-source software used to run conference submission and scheduling systems — lets any registered user hijack an organiser's account without the organiser clicking anything. The attack works by hiding malicious code inside a presentation submission title; when an organiser searches for talks, the code runs silently and can steal their session, accept talks automatically, or permanently strip their admin access. The flaw has been patched in pretalx version v2026.1.0, released 27 May 2026. If you run or organise a conference using pretalx, update to v2026.1.0 immediately — go to your server's admin panel or package manager and confirm the version number before accepting any new submissions. 🔥 #CyberNewsLive https://hackread.com/zero-click-pretalx-xss-hackers-hijack-conference-accounts/
Post summary
CVE-2026-41241 is a zero‑click XSS vulnerability that lets a registered user hijack an organiser’s account via a malicious presentation title; pretalx has released patch v2026.1.0, and users are urged to update immediately.



