PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12862 pretix CVE debrief

CVE-2026-12862 involves the passing of untrusted user data to Excel exports for administrators without proper sanitization, leading to a formula injection vulnerability. This vulnerability, with a CVSS score of 5.1, allows attackers to potentially compromise the environment of users who open the malicious Excel file. The vulnerability was published on June 22, 2026, and has been categorized as medium severity. Organizations using the affected product should prioritize reviewing and securing their Excel export functionalities to prevent exploitation.

Vendor
pretix
Product
Venueless
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-22
Original CVE updated
2026-06-23
Advisory published
2026-06-22
Advisory updated
2026-06-23

Who should care

Administrators and users of the affected product who generate or receive Excel exports are at risk. This vulnerability can lead to environment compromise for users who open malicious files. Therefore, IT administrators, security teams, and end-users who utilize Excel exports within the organization should be aware of this vulnerability and take necessary precautions.

Technical summary

The vulnerability arises from the lack of sanitization of user data when it is exported to Excel files. Attackers can inject malicious formulas into the Excel exports, which, when opened, can execute arbitrary actions. The CVSS:4.0 vector is AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X, indicating a medium severity level with limited impact and low exploitability.

Defensive priority

Medium priority due to limited exploitability but potential for environment compromise.

Recommended defensive actions

  • Review and update Excel export functionalities to properly sanitize user input.
  • Implement compensating controls such as restricting direct access to Excel files.
  • Monitor Excel export logs for suspicious activity.
  • Educate users on safe practices when opening files from untrusted sources.
  • Apply vendor-supported remediation when available.

Evidence notes

The primary evidence for this vulnerability comes from the CVE record and NVD detail pages. The vulnerability allows for formula injection via Excel exports for administrators. Verification of affected products and versions should be done through official vendor advisories and CVE details. The information provided indicates a medium severity but emphasizes the importance of securing user data in exports to prevent potential compromise.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12862 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12862

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12862 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12862

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/venueless/venueless/security/advisories/GHSA-5hw3-655h-7m86

    655498c3-6ec5-4f0b-aea6-853b334d05a6

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.