A vulnerability classified as critical was found in pretix up to 2026.4.5/2026.5.3/2026.6.0. This issue affects some unknown processing of the component Quick Setup. The manipulation results in permission issues.

This vulnerability was named CVE-2026-18028. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.