Information Exposure Vulnerability in Postiz by Gitroom
CVE-2026-107761

5.3MEDIUM

Key Information:

Vendor

Gitroomhq

Vendor
CVE Published:
11 October 2026

What is CVE-2026-107761?

Multiple API endpoints in Postiz reveal sensitive information, allowing unauthorized access to critical data elements. Specifically, the delete channel endpoint exposes the platform access token and refresh token, thereby potentially enabling third-party OAuth applications to misuse these credentials against user accounts. Furthermore, the user organizations endpoint inadvertently shares API keys with non-admin members, granting them the ability to interact with the organization's resources improperly. Both endpoints require valid authentication but safeguard against anonymous access and cross-tenant exploitation.

Affected Version(s)

postiz-app 0 < 2.25.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gilad Resisi
Enno Gelhaus
Gilad Resisi
.