What is CVE-2026-19264?
CVE-2026-19264 is a vulnerability in Postiz, an open-source social media scheduling tool, where an unauthenticated route serving local media fails to normalize paths and restrict access to the upload directory. This path traversal flaw allows an attacker to read arbitrary files from the server. Immediate patching or restricting the affected route is recommended.
Azərbaycanca: CVE-2026-19264, Postiz açıq mənbəli sosial media planlaşdırma alətində autentifikasiya tələb etməyən zəiflikdir. Zəiflik, lokaldakı media fayllarına xidmət edən marşrutda 'path traversal' imkanı yaradır və hücumçuya serverdəki ixtiyari faylları oxumağa imkan verir. Təcili olaraq tətbiqetməni yamamaq və ya bu marşrutu məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which software is affected by CVE-2026-19264, and what can an attacker do by exploiting it?
CVE-2026-19264 affects Postiz, the open-source social media scheduling tool. By exploiting this vulnerability, an attacker can read arbitrary files from the server without authentication.
What measures should be taken to mitigate CVE-2026-19264?
To mitigate this vulnerability, it is recommended to patch the application immediately or restrict the affected route.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.