CVE-2026-50165
Deferred Deferred - Pending Action

Improper Access Control in alf.io Exposes System Secrets

Vulnerability report for CVE-2026-50165, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. An Improper Access Control issue in versions prior to 2.0-M5-2605 allows an organization owner to read system-level configuration secrets through organization/event scoped "single configuration" endpoints. The affected endpoints require organization or event ownership, but they accept an arbitrary configuration key and then return the first matching value from a lookup that includes system-level configuration. As a result, an organization owner can retrieve secrets intended to be administrator-only, including the system API key when it is configured. Version 2.0-M5-2605 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
alf.io alf.io to 2.0-m5-2605 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Access Control issue in alf.io versions before 2.0-M5-2605. It allows an organization owner to read system-level configuration secrets through organization or event scoped endpoints. These endpoints should only return configuration for the specific organization or event but instead return the first matching value from a lookup that includes system-level secrets, such as the system API key.

Detection Guidance

Check if your alf.io version is prior to 2.0-M5-2605. Review logs for unauthorized access to system-level configuration endpoints by organization owners. Inspect network traffic for requests to /api/configuration or similar endpoints with arbitrary configuration keys.

Impact Analysis

If you are an organization owner using an affected version of alf.io, an attacker with organization ownership could exploit this to access sensitive system secrets like the system API key. This could lead to unauthorized access to system resources, data breaches, or further compromise of the ticket reservation system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR or HIPAA requirements for data protection and confidentiality. Exposure of system API keys or other secrets may result in non-compliance with these regulations, leading to legal and financial penalties.

Mitigation Strategies

Upgrade to alf.io version 2.0-M5-2605 or later. Review and rotate any exposed system API keys or secrets. Restrict access to configuration endpoints to administrators only. Monitor for suspicious activity from organization owners.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50165. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart