Skip to content
PSA-2026-Q3TCPKCVE-2026-48799GCVE-125-2026-Q3TCPKMay 23, 2026
4.8 Medium

Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook

Affected (1)

  • gitroomhqpostiz-app
    • ≥ 0Fixed in 2.21.8Affected

    All other versions: Unaffected

Mitigations

Workarounds

  • No workaround is currently known, other than upgrading to v2.21.8.

Solutions

  • Currently no solution, other than upgrading to v2.21.8, is known.

Overview

Postiz exposes a cryptocurrency payment IPN (Instant Payment Notification) handler that fails to verify the authenticity of incoming callbacks against the payment provider's shared secret. The endpoint accepts requests authenticated only by a token signed with an internal application key, which any platform user can obtain. Compounding this, the handler reads the target subscription identifier from the untrusted request body rather than from the verified token, allowing a caller to specify an arbitrary organization as the upgrade target.

A remote attacker with a low-privileged account can therefore cause the application to persist a lifetime PRO subscription entitlement against any organization of their choosing, without any payment being made or any signal of compromise reaching the legitimate payment provider. The vulnerability primarily impacts the integrity of subscription and billing state and results in revenue loss for the operator. It does not disclose user data or affect service availability.

Severity

CVSS v4
4.8 Medium
4.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln Confidentiality
None
Vuln Integrity
High
Vuln Availability
None
Sub Confidentiality
None
Sub Integrity
None
Sub Availability
None
CVSS v3
7.7 High
7.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None

Weaknesses (2)

References (2)

Credits (3)

  • Nedum
    Reporter · @nedu-m
  • Enno Gelhaus
    Coordinator · @egelhaus
  • Nevo David
    Remediation developer · @nevo-david

Context

Impacts

  • The attacker gains lifetime PRO access.

Timeline

  1. 05/22/2026 11:21

    Postiz has received the advisory.

  2. 05/22/2026 12:00

    Postiz has verified the vulnerability.

  3. 05/22/2026 12:16

    Postiz has developed and verified the fix.

  4. 05/22/2026 18:30

    Postiz has released the developed fix.

  5. 05/23/2026 12:25

    Postiz has released the advisory.

© 2026 Gelhaus Solutions