CVE-2026-48799

HIGH

Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook

Title source: cna
STIX 2.1

Description

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.

Scores

CVSS v3 7.7
EPSS 0.0016
EPSS Percentile 6.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-345 CWE-639
Status published
Products (1)
gitroomhq/postiz-app < 2.21.8
Published Jul 15, 2026
Tracked Since Jul 15, 2026