Search/CVE-2026-13223
CVE

CVE-2026-13223

Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

CVSS v3.1
EPSS
0.33%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 26, 2026
0.07pp
0.26% → 0.33% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Jun 25, 2026
Disclosure — published as a CVE record.