6.5

CVE-2026-19127

Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions

An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitroomHQ
Produkt postiz-app
Default Statusunaffected
Version 0
Version < 2.21.10
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.208
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
4cdc9741-f887-419a-a2fd-acbbd2729276 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://gadvisory.org/advisories/PSA-2026-NWZN9J
https://github.com/gitroomhq/postiz-app/commit/387d85dabe0223cd930714c19072a0aee58541ca
https://github.com/gitroomhq/postiz-app/releases/tag/v2.21.10