PT-2026-50122 · Postiz · Postiz

·

CVE-2026-48783

·

Published

2026-06-16

·

Updated

2026-06-17

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Postiz versions prior to 2.21.8
Description Postiz contains an unauthenticated billing-enforcement bypass. The endpoint '/public/modify-subscription' accepts a signed token and applies subscription-enforcement side effects to the organization referenced in the token's claims without verifying the token's intended purpose. While the persisted subscription tier cannot be changed, the issue allows the execution of enforcement-related side effects on the caller's own organization. These effects include adjusting team-member enablement state, disabling integrations that exceed the asserted plan's limits, and resetting the scheduled-post cron when the asserted plan is the free tier. The impact is limited to the attacker's own organization and cannot be redirected to other tenants.
Recommendations Update to version 2.21.8. As a temporary workaround, restrict access to the '/public/modify-subscription' endpoint.

Exploit

Fix

Insufficient Verification of Data Authenticity

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48783
GHSA-V4WR-4J8G-4HFJ

Affected Products

Postiz