CVE-2026-48799
Last modified
CVE-2026-48799 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment.
Description
Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| gitroomhq | postiz-app | < 2.21.8 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-48799?
How severe is CVE-2026-48799?
How do I fix CVE-2026-48799?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48790Turso CLI is the command line interface (CLI) to the open-so…5.5
- CVE-2026-48792pam_usb provides hardware authentication for Linux using ord…4.4
- CVE-2026-48793Jellyfin is an open source self hosted media server. Prior t…8.8
- CVE-2026-48794Authelia is an open-source authentication and authorization …1.3
- CVE-2026-48795AdonisJS is a TypeScript-first web framework. From 10.1.3 un…8.6
- CVE-2026-48797Backpropagate is a Python library for fine-tuning large lang…9.3
- CVE-2026-4880The Barcode Scanner (+Mobile App) – Inventory manager, Order…9.8
- CVE-2026-48800Notepad++ is a free and open-source source code editor. Prio…7.8
- CVE-2026-48801linkify-it is a links recognition library with full Unicode …7.5
- CVE-2026-48802python-engineio is a Python implementation of the Engine.IO …7.5
- CVE-2026-48804python-socketio is a Python implementation of the Socket.IO …7.5
- CVE-2026-48805Twig is a template language for PHP. Prior to 3.27.0, deprec…9.1
Are you affected by CVE-2026-48799?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
