← Vulnerability feed

Vulnerability record · CVE-2026-48799 · published 15 July 2026

CVE-2026-48799: Insufficient verification of data authenticity vulnerability

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.

7.7 CVSS 3.1 High EPSS 0.22% · top 89.0% CWE-345 · Insufficient verification of data authenticityCWE-639 · Insecure direct object reference Deferred
7.7CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
0Affected product versions listed by NVD
4References
15 Jul 2026Last modified by NVD

Description

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

References

Track CVE-2026-48799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-48799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.