
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14881 is a Broken Access Control vulnerability in pretix, an open-source ticketing software, that allows low-privileged authenticated users to access sensitive files belonging to other users by knowing the UUID of the file. The flaw affects pretix versions prior to 2025.8.3, 2025.9.0–2025.9.2, and 2025.10.0. It was published on December 19, 2025, with a patch released the same day. The vulnerability carries a CVSS v4.0 base score of 3.8 (Low) (GitHub Advisory, ENISA EUVD).
The root cause is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key (CWE-639), where multiple API endpoints failed to enforce proper ownership checks before serving files. An attacker with a low-privilege account can supply a known or guessed UUID in API requests to retrieve files that belong to other users, bypassing the intended access controls. The attack requires network access and low-level privileges, but no user interaction, and the attack requirements note that some preconditions must be present (AT:P). A fix was committed in the pretix repository (commit 4b56518) (GitHub Advisory, pretix Blog).
Successful exploitation allows a low-privileged attacker to read sensitive files uploaded by other users of the pretix platform, resulting in a high confidentiality impact on both the vulnerable and subsequent systems. There is no integrity or availability impact — the vulnerability is purely a data exposure issue. In a multi-tenant or event-management context, exposed files could include personally identifiable information (PII), ticket data, or other sensitive documents uploaded by organizers or attendees (GitHub Advisory, ENISA EUVD).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.038–0.063%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, ENISA EUVD).
GET /api/v1/files/<target-uuid>).Pretix released patched versions on December 18–19, 2025: 2025.8.3, 2025.9.3, and 2025.10.1. All users running versions prior to these releases should upgrade immediately. No configuration-based workaround is documented; upgrading to a patched version is the only recommended remediation. Additionally, administrators should audit API access logs for anomalous cross-user file access patterns (GitHub Advisory, pretix Blog).
The vulnerability received routine coverage from vulnerability tracking services including Vulners, CVEFeed, and CIRCL's Vulnerability Lookup shortly after disclosure. A brief post appeared on Bluesky via the CVE tracking account. No notable researcher commentary or significant media coverage has been identified beyond standard vulnerability database aggregation (CIRCL Mastodon).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."