THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-19264 (CRITICAL 9.8) — Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authenticati

[NVD] CVE-2026-19264 (CRITICAL 9.8) — Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authenticati

mednvdPublished 2026-08-07

CVE-2026-19264 CVSS: 9.8 CRITICAL Published: 2026-08-07T15:17:00.297

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing,

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19264