CVE-2026-48781 describes a critical vulnerability affecting Postiz versions before 2.21.8. The Skool plugin's integration callback improperly signs attacker-controlled JSON data into a JWT using the application's JWT_SECRET. The auth middleware trusts these claims without re-validating user identity from the database. This allows any authenticated user to create a SUPERADMIN session, granting full access to all Postiz components, including user data and social media accounts. The risk level is critical, as this enables complete system compromise. Affected software includes the Postiz platform and Skool plugin. Attackers can exploit this to impersonate organizations and post content under their names. Organizations using vulnerable versions should apply the latest patch immediately. Users should verify their Postiz version and update to 2.21.8 or later. No workarounds are available. This vulnerability requires no user interaction beyond initial authentication, making it particularly dangerous. Security teams should prioritize remediation to prevent unauthorized access and data exposure.