CVE-2026-107761
Channel tokens and organization API key exposed in API responses
Description
Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. The public API's channel delete returns the deleted integration row, including the channel's platform access token and refresh token. A third-party OAuth app permitted to delete a channel therefore receives that channel's social platform credentials and can use them against the connected account directly, outside Postiz. `GET /user/organizations` returns each organization row, including its API key, to every member of the organization. The API key is intended for admins only, so a member with a lower role can obtain it and call the public API on behalf of the organization. Both endpoints require a valid session, API key or OAuth token and are scoped to the caller's own organization. There is no anonymous access and no cross-tenant exposure.
INFO
Published Date :
Oct. 11, 2026, 4:16 p.m.
Last Modified :
Oct. 11, 2026, 4:16 p.m.
Remotely Exploit :
No
Source :
4cdc9741-f887-419a-a2fd-acbbd2729276
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 4.0 | MEDIUM | 4cdc9741-f887-419a-a2fd-acbbd2729276 | ||||
| CVSS 4.0 | MEDIUM | 4cdc9741-f887-419a-a2fd-acbbd2729276 |
Solution
- Limit returned fields to necessary data.
- Enforce granular authorization for API endpoints.
- Review and restrict access to sensitive fields.
- Update API to avoid returning secrets.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-107761.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-107761 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-107761
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-107761 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-107761 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 4cdc9741-f887-419a-a2fd-acbbd2729276
Oct. 11, 2026
Action Type Old Value New Value Added Description Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. The public API's channel delete returns the deleted integration row, including the channel's platform access token and refresh token. A third-party OAuth app permitted to delete a channel therefore receives that channel's social platform credentials and can use them against the connected account directly, outside Postiz. `GET /user/organizations` returns each organization row, including its API key, to every member of the organization. The API key is intended for admins only, so a member with a lower role can obtain it and call the public API on behalf of the organization. Both endpoints require a valid session, API key or OAuth token and are scoped to the caller's own organization. There is no anonymous access and no cross-tenant exposure. Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-201 Added CWE CWE-213 Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/107xxx/CVE-2026-107761.json">CVE-2026-107761</a> Added Reference https://gadvisory.org/advisories/PSA-2026-4QX1WG Added Reference https://github.com/gitroomhq/postiz-app/commit/8ad0df3df0f21299b8640568358c1b68c6464e4f Added Reference https://github.com/gitroomhq/postiz-app/releases/tag/v2.25.1