Vulnerability in Postiz Application Exposes Sensitive Credentials
CVE-2026-94456
9.1CRITICAL
What is CVE-2026-94456?
The Postiz application generates security-sensitive credentials using Math.random(), which is not cryptographically secure. This allows an unauthenticated OAuth dynamic client registration endpoint to leak client credentials. Attackers can collect and analyze the predictable output of the random number generator, thereby reconstructing its internal state. By doing so, they gain the capability to derive previously generated and future credential values, which may compromise the security of user and organization data.
Affected Version(s)
postiz-app 0 < 2.4.0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Santosh Kumar Puppala
Enno Gelhaus
Nevo David
