Information Exposure Vulnerability in Postiz by Gitroom
CVE-2026-107761
5.3MEDIUM
What is CVE-2026-107761?
Multiple API endpoints in Postiz reveal sensitive information, allowing unauthorized access to critical data elements. Specifically, the delete channel endpoint exposes the platform access token and refresh token, thereby potentially enabling third-party OAuth applications to misuse these credentials against user accounts. Furthermore, the user organizations endpoint inadvertently shares API keys with non-admin members, granting them the ability to interact with the organization's resources improperly. Both endpoints require valid authentication but safeguard against anonymous access and cross-tenant exploitation.
Affected Version(s)
postiz-app 0 < 2.25.1
