Vulnerability in Postiz Application Exposes Sensitive Credentials
CVE-2026-94456

9.1CRITICAL

Key Information:

Vendor

Gitroomhq

Vendor
CVE Published:
22 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-94456?

The Postiz application generates security-sensitive credentials using Math.random(), which is not cryptographically secure. This allows an unauthenticated OAuth dynamic client registration endpoint to leak client credentials. Attackers can collect and analyze the predictable output of the random number generator, thereby reconstructing its internal state. By doing so, they gain the capability to derive previously generated and future credential values, which may compromise the security of user and organization data.

Affected Version(s)

postiz-app 0 < 2.4.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Santosh Kumar Puppala
Enno Gelhaus
Nevo David
.