Unauthorized Access to Postiz Endpoint Without Session Validation
CVE-2026-94455

7.1HIGH

Key Information:

Vendor

Gitroomhq

Vendor
CVE Published:
22 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-94455?

A vulnerability exists in Postiz that allows unauthorized access to an HTTP endpoint intended for provisioning enterprise and reseller organizations. This endpoint can be reached without any session validation since the authentication middleware is only applied to a specific list of controllers, and the enterprise controller is not included on that list. The system's only check involves the presence of a token with a valid signature from the instance secret, which does not verify the purpose or identity associated with that token. As a result, any user session token can satisfy this condition. When exploited, this vulnerability can lead to the creation of a new organization with the highest subscription tier, along with an organization-owner account, thus exposing the API key valid for further unauthorized actions.

Affected Version(s)

postiz-app 0 < 2.4.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Santosh Kumar Puppala
Enno Gelhaus
Nevo David
.