SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18029

MEDIUM · CVSS 6.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The vulnerability arises from improper validation of payment status responses in the GiroCheckout payment integration, allowing an attacker to exploit this flaw by reusing a valid payment response to gain unauthorized access to multiple tickets. This could lead to significant financial losses and unauthorized access to services. Organizations utilizing this payment integration should prioritize addressing this issue to mitigate potential fraud and ensure secure transaction processing.

CVE
CVE-2026-18029
Severity
MEDIUM
CVSS
6.3
EPSS
0.21%

Original NVD Description

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.