PatchSiren

Attendize CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Attendize CVE published 2026-08-10

CVE-2026-72690

The CVE-2026-72690 record details an improper authorization vulnerability in Attendize, a software used for event management. This vulnerability, tracked as CVE-2026-72690, allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events. The issue arises from the postCreateEventQuestion method loading the target event without tenant-isolation scope, [truncated]