Description
Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive.

The public API's channel delete returns the deleted integration row, including the channel's platform access token and refresh token. A third-party OAuth app permitted to delete a channel therefore receives that channel's social platform credentials and can use them against the connected account directly, outside Postiz.

`GET /user/organizations` returns each organization row, including its API key, to every member of the organization. The API key is intended for admins only, so a member with a lower role can obtain it and call the public API on behalf of the organization.

Both endpoints require a valid session, API key or OAuth token and are scoped to the caller's own organization. There is no anonymous access and no cross-tenant exposure.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized exposure of secret tokens and organization API keys
Action: Apply patch
AI Analysis

Impact

The vulnerability arises because certain Postiz API endpoints return the entire database row for the resources they operate on, rather than limiting the response to the fields required by the client. As a result, callers receive sensitive data that they are not authorized to see, including channel platform access tokens, refresh tokens, and organization API keys. This data leakage can enable an attacker to compromise connected social platform accounts and to impersonate the organization in external services. The weakness is consistent with the CWE-201 ‘Information Exposure Through Disparate Data Sources’ and CWE-213 ‘Improper Verification of Cryptographic Credentials’, which describe comparable patterns of exposing confidential data and mishandling credentials.

Affected Systems

The affected product is GitroomHQ’s Postiz-app. No specific minor versions are enumerated in the CVE, but the published release v2.25.1 contains the fix that removes the leaked fields from the API responses.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session, API key, or OAuth token and is limited to the caller’s own organization; there is no anonymous or cross‑tenant access. Likely attack vectors involve a third‑party OAuth application that has permission to delete a channel and can thus harvest its credentials, or a lower‑role organization member who can retrieve the organization API key through the GET /user/organizations endpoint. Given the scope and the necessity of valid authentication, the risk to individual tenants is moderate but could be serious if credentials are abused.

Generated by OpenCVE AI on October 11, 2026 at 16:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to GitroomHQ Postiz-app v2.25.1 or later which removes sensitive information from API responses.
  • Revoke or restrict third‑party OAuth applications that possess permission to delete channels until the patch is applied.
  • Enforce role‑based filtering so that only administrators can retrieve organization API keys via GET /user/organizations, preventing lower‑role members from accessing these secrets.

Generated by OpenCVE AI on October 11, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Gitroomhq
Gitroomhq postiz-app
Vendors & Products Gitroomhq
Gitroomhq postiz-app

Sun, 11 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. The public API's channel delete returns the deleted integration row, including the channel's platform access token and refresh token. A third-party OAuth app permitted to delete a channel therefore receives that channel's social platform credentials and can use them against the connected account directly, outside Postiz. `GET /user/organizations` returns each organization row, including its API key, to every member of the organization. The API key is intended for admins only, so a member with a lower role can obtain it and call the public API on behalf of the organization. Both endpoints require a valid session, API key or OAuth token and are scoped to the caller's own organization. There is no anonymous access and no cross-tenant exposure.
Title Channel tokens and organization API key exposed in API responses
Weaknesses CWE-201
CWE-213
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Gitroomhq Postiz-app
cve-icon MITRE

Status: PUBLISHED

Assigner: postiz

Published:

Updated: 2026-10-11T15:24:16.835Z

Reserved: 2026-10-08T19:04:47.306Z

Link: CVE-2026-107761

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T16:16:30.490

Modified: 2026-10-11T16:16:30.490

Link: CVE-2026-107761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T16:30:17Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-213

    Exposure of Sensitive Information Due to Incompatible Policies