Junglewise Threat Intelligence

CVE-2026-48781: Postiz privilege escalation via JWT forgery in Skool integration

CVE-2026-48781 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Gitroom Postiz. Vendors: Gitroom.

Executive brief

Postiz, an AI-powered social media scheduling tool, contained a critical flaw in its Skool integration component. An attacker with a standard user account could manipulate the system into granting them 'Super Admin' privileges. This would allow the attacker to take full control of the platform, access other users' data, and post content to social media accounts linked to the service.

Technical details

A vulnerability in the Skool integration callback of Postiz allowed for JWT forgery and subsequent authentication bypass. The application signed attacker-provided JSON data into a session JWT using the internal JWT_SECRET without sufficient validation. Furthermore, the authentication middleware trusted the claims within the JWT (such as 'isSuperAdmin') without verifying the user's actual status against the database. An authenticated attacker could exploit this to elevate their privileges to 'SUPERADMIN' and impersonate any organization. The vulnerability is tracked as CWE-302, CWE-345, and CWE-863. It has been patched in version 2.21.8 by ensuring claims are properly validated and users are re-resolved.

Affected products

  • gitroomhq postiz-app < 2.21.8

Timeline

  • 2026-05-22: disclosed: Postiz received the vulnerability report.
  • 2026-05-22: patched: Fix developed and verified.
  • 2026-06-17: advisory: CVE-2026-48781 published.

References

Related threats