CVE-2026-48799

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-15 17:16

Updated : 2026-07-15 20:54


NVD link : CVE-2026-48799

Mitre link : CVE-2026-48799

CVE.ORG link : CVE-2026-48799


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-639

Authorization Bypass Through User-Controlled Key