# CVE-2026-11764

## Summary

- **CVE ID:** CVE-2026-11764
- **Severity:** LOW
- **CVSS Score:** 3.6 (CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U)
- **CWE:** CWE-280
- **Published:** Jun 9, 2026
- **Last Modified:** Jun 9, 2026

## Description

When creating an export of all reusable media, the secrets of connected 
gift cards were included in the export even if the user creating the 
export does not have permission to view gift cards. This is inconsistent
 with the UI and API where only the first letters of the gift card 
secret are shown. Therefore, it allows circumventing a permission 
boundary.

## Affected Products

- pretix — pretix (2024.1.0)
- pretix — pretix (2026.3.0)
- pretix — pretix (2026.4.0)
- pretix — pretix (2026.5.0)

## References

- [CNA](https://pretix.eu/about/en/blog/20260609-release-2026-5-1/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._