# CVE-2026-12862

## Summary

- **CVE ID:** CVE-2026-12862
- **Severity:** MEDIUM
- **CVSS Score:** 5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N)
- **CWE:** CWE-148
- **Published:** Jun 22, 2026
- **Last Modified:** Jun 22, 2026

## Description

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

## Affected Products

- pretix — Venueless (0.0.0)

## References

- [CNA](https://github.com/venueless/venueless/security/advisories/GHSA-5hw3-655h-7m86)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.38%
- **EPSS Percentile:** 31.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._