{"document":{"category":"csaf_vex","csaf_version":"2.0","title":"CVE-2026-13602: Session takeover vulnerability","publisher":{"category":"vendor","name":"HarborGuard Database","namespace":"https://database.harborguard.co"},"tracking":{"id":"CVE-2026-13602","status":"final","version":"1","initial_release_date":"2026-07-01T13:45:30.615Z","current_release_date":"2026-07-01T15:27:00.431Z","revision_history":[{"date":"2026-07-01T13:45:30.615Z","number":"1","summary":"Initial machine-readable export from HarborGuard."}]},"distribution":{"tlp":{"label":"WHITE"},"text":"Public CVE data; freely redistributable."},"notes":[{"category":"description","text":"We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:\n\n\n\n\n\n\n\n  *  \n\n\nThe payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay\n contain a code path that is intended for the transport of session \nparameters from a tab with isolated cookies (e.g. in the pretix widget) \nto a new tab. For this purpose, a set of session parameters is \ncryptographically signed and then passed to the new tab as a URL \nparameter. The plugins perform no further validation of the session \nparameters, other than the cryptographic signature being valid. This is \nfixed with the releases issued today by strictly validating that no \nsession parameters outside of the scope of the respective plugin may be \nset.\n\n\n\n\n  *  \n\n\nAn unrelated feature in the core system is used to generate redirect links that obfuscate any Referer\n headers for outgoing links to prevent leakage of secrets in URLs. This \nredirect page also requires cryptographically signed parameters. \nUnfortunately, it uses the same key and salt for the signature as the \npreviously mentioned feature in the payment integration plugins. A \nmotivated attacker with access to at least one event in the backend can \ntrick the system into cryptographically signing arbitrary content using \nspecially crafted links. In combination with the previous issue, the \nattacker could use this to set and modify arbitrary parameters on their \nuser session by injecting the signed parameters into the feature of the \npayment providers. This is fixed with the releases issued today by using\n different salts for the signature for each plugin and feature.\n\n\n\n\n  *  \n\n\nA third, unrelated feature in the core system is used for admin users\n to act on behalf of another user, mostly for debugging purposes. With \nbeing able to insert arbitrary parameters into a session, an attacker \ncan abuse this feature to change their session from their actual user to\n any user in the system by guessing a valid user ID. This is fixed with\n the release today by requiring unguessable information to be contained \nin the session of the user to switch to.","title":"CVE description"}],"references":[{"category":"self","summary":"CVE-2026-13602 on HarborGuard Database","url":"https://database.harborguard.co/cve/CVE-2026-13602"},{"category":"external","summary":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-13602"},{"category":"external","summary":"pretix.eu","url":"https://pretix.eu/about/en/blog/20260701-release-2026-5-3/"}]},"product_tree":{"branches":[{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix","branches":[{"category":"product_version_range","name":">=4.14.0 <2026.3.5","product":{"name":"pretix pretix >=4.14.0 <2026.3.5","product_id":"CSAFPID-1","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":">=2026.4.0 <2026.4.5","product":{"name":"pretix pretix >=2026.4.0 <2026.4.5","product_id":"CSAFPID-2","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":">=2026.5.0 <2026.5.3","product":{"name":"pretix pretix >=2026.5.0 <2026.5.3","product_id":"CSAFPID-3","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:*"}}}]}]},{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix-mollie","branches":[{"category":"product_version_range","name":"<2.5.7","product":{"name":"pretix pretix-mollie <2.5.7","product_id":"CSAFPID-4","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix-mollie:*:*:*:*:*:*:*:*"}}}]}]},{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix-oppwa","branches":[{"category":"product_version_range","name":"<1.4.4","product":{"name":"pretix pretix-oppwa <1.4.4","product_id":"CSAFPID-5","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix-oppwa:*:*:*:*:*:*:*:*"}}}]}]},{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix-bitpay","branches":[{"category":"product_version_range","name":"<1.5.3","product":{"name":"pretix pretix-bitpay <1.5.3","product_id":"CSAFPID-6","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix-bitpay:*:*:*:*:*:*:*:*"}}}]}]},{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix-payone","branches":[{"category":"product_version_range","name":"<1.4.3","product":{"name":"pretix pretix-payone <1.4.3","product_id":"CSAFPID-7","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix-payone:*:*:*:*:*:*:*:*"}}}]}]},{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix-secuconnect","branches":[{"category":"product_version_range","name":"<1.0.4","product":{"name":"pretix pretix-secuconnect <1.0.4","product_id":"CSAFPID-8","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix-secuconnect:*:*:*:*:*:*:*:*"}}}]}]},{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix-sofort","branches":[{"category":"product_version_range","name":"<1.4.2","product":{"name":"pretix pretix-sofort <1.4.2","product_id":"CSAFPID-9","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix-sofort:*:*:*:*:*:*:*:*"}}}]}]},{"category":"vendor","name":"pretix","branches":[{"category":"product_name","name":"pretix-saferpay","branches":[{"category":"product_version_range","name":"<1.6.3","product":{"name":"pretix pretix-saferpay <1.6.3","product_id":"CSAFPID-10","product_identification_helper":{"cpe":"cpe:2.3:a:pretix:pretix-saferpay:*:*:*:*:*:*:*:*"}}}]}]}]},"vulnerabilities":[{"cve":"CVE-2026-13602","title":"Session takeover vulnerability","notes":[{"category":"description","text":"We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:\n\n\n\n\n\n\n\n  *  \n\n\nThe payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay\n contain a code path that is intended for the transport of session \nparameters from a tab with isolated cookies (e.g. in the pretix widget) \nto a new tab. For this purpose, a set of session parameters is \ncryptographically signed and then passed to the new tab as a URL \nparameter. The plugins perform no further validation of the session \nparameters, other than the cryptographic signature being valid. This is \nfixed with the releases issued today by strictly validating that no \nsession parameters outside of the scope of the respective plugin may be \nset.\n\n\n\n\n  *  \n\n\nAn unrelated feature in the core system is used to generate redirect links that obfuscate any Referer\n headers for outgoing links to prevent leakage of secrets in URLs. This \nredirect page also requires cryptographically signed parameters. \nUnfortunately, it uses the same key and salt for the signature as the \npreviously mentioned feature in the payment integration plugins. A \nmotivated attacker with access to at least one event in the backend can \ntrick the system into cryptographically signing arbitrary content using \nspecially crafted links. In combination with the previous issue, the \nattacker could use this to set and modify arbitrary parameters on their \nuser session by injecting the signed parameters into the feature of the \npayment providers. This is fixed with the releases issued today by using\n different salts for the signature for each plugin and feature.\n\n\n\n\n  *  \n\n\nA third, unrelated feature in the core system is used for admin users\n to act on behalf of another user, mostly for debugging purposes. With \nbeing able to insert arbitrary parameters into a session, an attacker \ncan abuse this feature to change their session from their actual user to\n any user in the system by guessing a valid user ID. This is fixed with\n the release today by requiring unguessable information to be contained \nin the session of the user to switch to.","title":"CVE description"}],"product_status":{"known_affected":["CSAFPID-1","CSAFPID-2","CSAFPID-3","CSAFPID-4","CSAFPID-5","CSAFPID-6","CSAFPID-7","CSAFPID-8","CSAFPID-9","CSAFPID-10"]},"scores":[{"cvss_v4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U","baseScore":7.7,"baseSeverity":"HIGH"},"products":["CSAFPID-1","CSAFPID-2","CSAFPID-3","CSAFPID-4","CSAFPID-5","CSAFPID-6","CSAFPID-7","CSAFPID-8","CSAFPID-9","CSAFPID-10"]}],"remediations":[{"category":"vendor_fix","details":"Update to a fixed version: 1.0.4, 1.4.2, 1.4.3, 1.4.4, 1.5.3, 1.6.3, 2.5.7, 2026.3.5, 2026.4.5, 2026.5.3.","product_ids":["CSAFPID-1","CSAFPID-2","CSAFPID-3","CSAFPID-4","CSAFPID-5","CSAFPID-6","CSAFPID-7","CSAFPID-8","CSAFPID-9","CSAFPID-10"]}]}]}