Description
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.
Timeline
- 2026-06-21 18:00 UTC - Postiz has discovered the vulnerability.
- 2026-06-22 13:20 UTC - Postiz has developed and verified the fix.
- 2026-06-22 13:44 UTC - Postiz has created the release and published the advisory.
- 2026-08-06 16:04 UTC - Postiz has assigned CVE-2026-19127 for this advisory.
Workarounds
- No workaround other than upgrading to v2.21.10 is currently known.
Mitigations
- No solution other than upgrading to v2.21.10 is currently known.
Vulnerable configurations
- Stripe has to be configured for this to apply.
References
Description
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.
Timeline
Workarounds
Mitigations
Vulnerable configurations
References