PSA-2026-Q3TCPKCVE-2026-48799GCVE-125-2026-Q3TCPKMay 23, 2026Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
Affected (1)
- gitroomhqpostiz-app
- ≥ 0Fixed in 2.21.8Affected
All other versions: Unaffected
Mitigations
Workarounds
- No workaround is currently known, other than upgrading to v2.21.8.
Solutions
- Currently no solution, other than upgrading to v2.21.8, is known.
Overview
Postiz exposes a cryptocurrency payment IPN (Instant Payment Notification) handler that fails to verify the authenticity of incoming callbacks against the payment provider's shared secret. The endpoint accepts requests authenticated only by a token signed with an internal application key, which any platform user can obtain. Compounding this, the handler reads the target subscription identifier from the untrusted request body rather than from the verified token, allowing a caller to specify an arbitrary organization as the upgrade target.
A remote attacker with a low-privileged account can therefore cause the application to persist a lifetime PRO subscription entitlement against any organization of their choosing, without any payment being made or any signal of compromise reaching the legitimate payment provider. The vulnerability primarily impacts the integrity of subscription and billing state and results in revenue loss for the operator. It does not disclose user data or affect service availability.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- Low
- User Interaction
- None
- Vuln Confidentiality
- None
- Vuln Integrity
- High
- Vuln Availability
- None
- Sub Confidentiality
- None
- Sub Integrity
- None
- Sub Availability
- None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- Scope
- Changed
- Confidentiality
- None
- Integrity
- High
- Availability
- None
Weaknesses (2)
References (2)
Credits (3)
- NedumReporter · @nedu-m
- Enno GelhausCoordinator · @egelhaus
- Nevo DavidRemediation developer · @nevo-david
Context
Impacts
The attacker gains lifetime PRO access.
Timeline
- 05/22/2026 11:21
Postiz has received the advisory.
- 05/22/2026 12:00
Postiz has verified the vulnerability.
- 05/22/2026 12:16
Postiz has developed and verified the fix.
- 05/22/2026 18:30
Postiz has released the developed fix.
- 05/23/2026 12:25
Postiz has released the advisory.