CVE-2026-48781
gitroomhq postiz-app
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, including users registered to the specific instance and the ability to post in the name of the victim's social media...
- CVSS
- 9.9
- EPSS
- 0.21% 11.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.17