Account Takeover Flaw in Pretalx CFP Tool Let Attackers Accept Any Conference Talk
An account takeover vulnerability in the open-source call-for-papers platform Pretalx could allow an unauthenticated attacker to manipulate submission outcomes, researchers at Novee have found.

Researchers at Novee disclosed an account takeover vulnerability in Pretalx, the open-source conference management platform widely used by technical communities to handle call-for-papers (CFP) submissions and speaker scheduling. The flaw, if exploited, would allow an attacker to assume control of organiser accounts and, consequently, approve or reject any submitted talk — a condition Novee described as yielding a theoretical 100 percent talk acceptance rate.
Pretalx is maintained as an open-source project and is used by a range of academic and developer conferences to manage submission workflows. The vulnerability was identified by Novee security researchers (the firm has not yet published a full technical advisory with a CVE identifier at time of writing, though one is expected through standard coordinated disclosure channels).
The mechanism of the flaw centres on account takeover. An attacker who successfully exploits the issue could impersonate an event organiser with full administrative rights over a given CFP instance. That access encompasses the ability to accept or decline submissions, alter speaker data, and potentially access contact information provided by submitters during the application process. So the practical consequences extend well beyond talk scheduling.
From a compliance standpoint, any Pretalx deployment that collects personally identifiable information from speakers — names, email addresses, biographical details — would ordinarily fall within the scope of data protection obligations, including, where applicable, the General Data Protection Regulation (GDPR) and, in the United Kingdom, the Data Protection Act 2018. Operators running self-hosted Pretalx instances carry controller-level responsibilities under those frameworks, meaning a breach arising from this vulnerability could trigger notification obligations to the relevant supervisory authority within 72 hours of becoming aware, as stipulated under Article 33 of the GDPR.
The Novee disclosure does not, at this stage, indicate that active exploitation has been observed in the wild. But the open-source distribution model for Pretalx means that remediation pace will vary considerably across the operator base (a common challenge with self-hosted tooling), and organisations that have not yet applied the patched release should treat this as a priority update.
Pretalx maintainers have issued a corrected release; administrators running any version prior to that patch should consult the Pretalx GitHub releases page for update instructions. And while coordinated vulnerability disclosure has worked as intended here, the incident is a reminder that CFP platforms hold more sensitive data than their relatively modest profile might suggest.
But the broader policy question is whether event organisers — many of them volunteer-run open-source communities — have adequate patch management practices for the infrastructure they operate. That question sits outside the scope of any single disclosure.
Operators awaiting a formal CVE assignment can monitor the NVD vulnerability database for the Pretalx entry as coordinated disclosure proceeds. The comment period for any potential GDPR supervisory action would begin from the date an affected organiser became aware of compromise; the 72-hour notification clock under Article 33 starts at that point.



