CVE-2026-48783 is a medium-severity vulnerability in Postiz, an AI social media scheduling tool. The issue, fixed in version 2.21.8, involves an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint could not change the persisted subscription [truncated]
CVE-2026-48781 is a critical vulnerability in Postiz, an AI social media scheduling tool. Versions prior to 2.21.8 are affected, allowing attackers to forge a SUPERADMIN session and impersonate arbitrary organizations. This vulnerability, with a CVSS score of 9.9, enables full access to all parts of Postiz, including user data and social media channels. The issue arises from the Skool integration callback [truncated]