5.3
MEDIUM CVSS 4.0
CVE-2026-107761
Channel tokens and organization API key exposed in API responses
Description

Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. The public API's channel delete returns the deleted integration row, including the channel's platform access token and refresh token. A third-party OAuth app permitted to delete a channel therefore receives that channel's social platform credentials and can use them against the connected account directly, outside Postiz. `GET /user/organizations` returns each organization row, including its API key, to every member of the organization. The API key is intended for admins only, so a member with a lower role can obtain it and call the public API on behalf of the organization. Both endpoints require a valid session, API key or OAuth token and are scoped to the caller's own organization. There is no anonymous access and no cross-tenant exposure.

INFO

Published Date :

Oct. 11, 2026, 4:16 p.m.

Last Modified :

Oct. 11, 2026, 4:16 p.m.

Remotely Exploit :

No

Source :

4cdc9741-f887-419a-a2fd-acbbd2729276
Affected Products

The following products are affected by CVE-2026-107761 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Gitroom postiz
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 4.0 MEDIUM 4cdc9741-f887-419a-a2fd-acbbd2729276
CVSS 4.0 MEDIUM 4cdc9741-f887-419a-a2fd-acbbd2729276
Solution
Restrict sensitive data exposure by implementing proper access controls and limiting returned fields.
  • Limit returned fields to necessary data.
  • Enforce granular authorization for API endpoints.
  • Review and restrict access to sensitive fields.
  • Update API to avoid returning secrets.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-107761.

URL Resource
https://gadvisory.org/advisories/PSA-2026-4QX1WG
https://github.com/gitroomhq/postiz-app/commit/8ad0df3df0f21299b8640568358c1b68c6464e4f
https://github.com/gitroomhq/postiz-app/releases/tag/v2.25.1
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-107761 is associated with the following CWEs:

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-107761 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-107761 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 4cdc9741-f887-419a-a2fd-acbbd2729276

    Oct. 11, 2026

    Action Type Old Value New Value
    Added Description Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. The public API's channel delete returns the deleted integration row, including the channel's platform access token and refresh token. A third-party OAuth app permitted to delete a channel therefore receives that channel's social platform credentials and can use them against the connected account directly, outside Postiz. `GET /user/organizations` returns each organization row, including its API key, to every member of the organization. The API key is intended for admins only, so a member with a lower role can obtain it and call the public API on behalf of the organization. Both endpoints require a valid session, API key or OAuth token and are scoped to the caller's own organization. There is no anonymous access and no cross-tenant exposure.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-201
    Added CWE CWE-213
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/107xxx/CVE-2026-107761.json">CVE-2026-107761</a>
    Added Reference https://gadvisory.org/advisories/PSA-2026-4QX1WG
    Added Reference https://github.com/gitroomhq/postiz-app/commit/8ad0df3df0f21299b8640568358c1b68c6464e4f
    Added Reference https://github.com/gitroomhq/postiz-app/releases/tag/v2.25.1
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.