CVE-2026-19127

MEDIUM CVSS 3.1: 6.5 EPSS 0.29%
Updated Aug 07, 2026
Gitroomhq
Parameter Value
CVSS 6.5 (MEDIUM)
Type CWE-345 (Insufficient Verification of Data)
Vendor Gitroomhq
Public PoC No

An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

gitroomhq:postiz-app