Security Advisory

CVE-2026-18029

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-28 10:39:29
Last updated 2026-07-28 12:36:18
Assigner rami.io
CVSS score not scored
State PUBLISHED

Description

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.