HIGH

CVE-2026-72690

2026-08-10 CVSS v3.1
CVSS
7.1

Description

An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events via the POST /event/{event_id}/question/create endpoint. The postCreateEventQuestion method loads the target event without the tenant-isolation scope, enabling cross-tenant writes; the injected question cannot be removed by the victim because the victim's account-scoped delete path cannot resolve a question owned by another tenant.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.25%
Probability of exploitation in next 30 days
17.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE