← Back to CVE Registry
CVE-2026-14842unrated[patched]
Unauthenticated Payment Bypass via Token Detachment
TARGET ECOSYSTEM / VENDOREvents Made Easy
AFFECTED PRODUCTEvents Made Easy (< 3.1.2)
CWE CLASSIFICATIONCWE-284: Improper Access Control
PUBLISHED DATE2026-07-07
ADVISORY / CNAWPScan Advisory (CNA) ↗
Summary
Events Made Easy (< 3.1.2) does not properly bind the payment authorization token to the specific payment record being charged. This allows an unauthenticated attacker to pay a low amount for a cheap booking while manipulating the request to have a separate, higher-priced booking marked as fully paid.
Official Status
- CNA Rating: Unrated
- Impact: Unauthenticated Payment Bypass
- Fixed Version: 3.1.2