CVEPublished 2026-07-28Modified 2026-07-280 articles on news4 live referencesNVD data

CVE-2026-18028

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
Description

The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the given event. An attacker could use a well-timed request to create products, quotas, set bank transfer configuration, or connect a stripe account to an event they do not have access to.

Timeline
Published 2026-07-28
Modified 2026-07-28

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-18028 on GitHub.
We haven't classified any articles referencing CVE-2026-18028 yet. The external references above still apply.