HIGH
Attendize
CVE published 2026-08-10
CVE-2026-72690
The CVE-2026-72690 record details an improper authorization vulnerability in Attendize, a software used for event management. This vulnerability, tracked as CVE-2026-72690, allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events. The issue arises from the postCreateEventQuestion method loading the target event without tenant-isolation scope, [truncated]