Unauthorized Access to Postiz Endpoint Without Session Validation
CVE-2026-94455
What is CVE-2026-94455?
A vulnerability exists in Postiz that allows unauthorized access to an HTTP endpoint intended for provisioning enterprise and reseller organizations. This endpoint can be reached without any session validation since the authentication middleware is only applied to a specific list of controllers, and the enterprise controller is not included on that list. The system's only check involves the presence of a token with a valid signature from the instance secret, which does not verify the purpose or identity associated with that token. As a result, any user session token can satisfy this condition. When exploited, this vulnerability can lead to the creation of a new organization with the highest subscription tier, along with an organization-owner account, thus exposing the API key valid for further unauthorized actions.
Affected Version(s)
postiz-app 0 < 2.4.0
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
