world is able to trigger deletion of user accounts in other worlds.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pretix
Pretix venueless |
|
| Vendors & Products |
Pretix
Pretix venueless |
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 05 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds. | |
| Title | API allows deletion of users of other instance | |
| Weaknesses | CWE-653 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2026-04-06T14:33:34.105Z
Reserved: 2026-04-05T12:25:52.821Z
Link: CVE-2026-5599
Updated: 2026-04-06T14:33:16.090Z
Status : Awaiting Analysis
Published: 2026-04-05T13:17:15.123
Modified: 2026-04-07T13:20:35.010
Link: CVE-2026-5599
No data.
OpenCVE Enrichment
Updated: 2026-04-06T21:56:46Z