216.73.216.10

CVE-2026-48781

· Published 17/06/2026 15:20 · Author: The MITRE Corporation

Labels: CVE-2026-48781 2026-06-17CVE-2026-48781CWE-302[email protected]

Essential information

Published
17/06/2026 15:20
Modified
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.9 CRITICAL (v3.1)
CISA KEV
No
CWE
CWE-302
EPSS (First)
P17.3% ?EPSS percentile: rank of this vulnerability versus all others. Higher percentile = more likely to be exploited. Learn more (score 0.00262)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, including users registered to the specific instance and the ability to post in the name of the victim's social media channels added to that Postiz instance. This issue has been fixed in version 2.21.8.

NVD status

NVD
View on NVD