tixplus-cache-exposure-2026 · Disclosed 2026-10-01
チケットプラス: data exposure and authorization boundaries
A cache change intended to reduce load caused cross-user information display during concurrent access. Up to 107 data owners and 322 viewers are separate scopes. Their sum is not a confirmed leaked-person count.
Outcome: Exposure / potential leak. Third-party theft unconfirmed.
Entry path and evidence
- Reported fact
A cache change intended to reduce load caused cross-user information display during concurrent access.
[s1]1. 発生経緯 / 4. 影響を受けた可能性のあるお客様 - Reported fact
Up to 107 data owners and 322 viewers are separate scopes. Their sum is not a confirmed leaked-person count.
[s1]1. 発生経緯 / 4. 影響を受けた可能性のあるお客様
Timeline
Reported response
- Reported fact
The service was suspended, configuration corrected, and service resumed on September 30.
[s1]1. 発生経緯 / 4. 影響を受けた可能性のあるお客様
Evidence relevant to prevention
Operational controls to inspect
Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
Overlap and the actual count displayed to other people are undisclosed.
Sources
[s1] チケットプラス · Primary source
チケットプラス:事故に関する公表資料 ↗Reviewed 2026-10-09