CVE-2026-48799

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.
Configurations

No configuration.

History

15 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 17:16

Updated : 2026-07-15 20:54


NVD link : CVE-2026-48799

Mitre link : CVE-2026-48799

CVE.ORG link : CVE-2026-48799


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-639

Authorization Bypass Through User-Controlled Key