CVE-2026-19264Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded only once they reach the handler, restoring the traversal at the filesystem call. An unauthenticated remote attacker can therefore read any file readable by the application process, including the process environment, which exposes the JWT signing secret, the database connection string, and connected provider and billing secrets. Because session tokens are signed with that secret and carry no expiry, this allows forging a non-expiring session as any user, including an administrator, without a password.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo
    Patch

    📅 Postiz users: CVE-2026-19264 is a critical path traversal via URL-encoded separators on /uploads — no auth needed to read arbitrary files and take over your instance. Patch to v2.22.1 now. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-19264?utm_campaign=x https://t.co/dgeVl0jV4h

    Post summary

    The post warns that CVE‑2026‑19264 is a critical path traversal on a Postiz instance and advises updating to v2.22.1 to remediate the issue.

    00000113
    879 followersView on X

Explore more