ExploitMatch
Back

CVE-2026-101267

Monitor on ThreatCluster

Description

A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.