CVE-2026-18029
CVE-2026-18029 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-841.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.3)
- EPSS exploit prediction: 0% (11th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-841
- Published:
- Last modified:
Description
Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
Frequently asked questions
- What is CVE-2026-18029?
- Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
- How severe is CVE-2026-18029?
- CVE-2026-18029 has a CVSS 4.0 base score of 6.3, rated medium severity.
- Is CVE-2026-18029 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (11th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-18029?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-18029 published?
- CVE-2026-18029 was published on 2026-07-28 and last updated on 2026-07-30.
References
Other CWE-841 vulnerabilities
- CVE-2026-3130 — Critical (CVSS 9.8): Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated…
- CVE-2025-48481 — Critical (CVSS 9.8): FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated…
- CVE-2022-2105 — Critical (CVSS 9.4): Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication,…
- CVE-2026-34582 — Critical (CVSS 9.1): Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData…
- CVE-2025-48476 — High (CVSS 8.8): FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user…
- CVE-2025-48477 — High (CVSS 8.1): FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic…