
Added to the growing list of "weak randomness, real breach" bugs: postiz-app generated OAuth secrets with Math.random (CVSS 9.1). CVE-2026-94456 means an unauthenticated attacker can harvest enough PRNG output from a public endpoint to reconstruct the internal state and predict other users' OAuth tokens, client secrets, API keys, and PKCE verifiers. Update postiz-app now. Details: http://vulntracker.io/cves/CVE-2026-94456 #Postiz #CVE #OAuth #InfoSec #CyberSecurity
