Sceawere

Vulnerability Detail

CVE-2026-104412UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Improper Authorization Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
11h ago
Vendor
TryGhost
Product
Ghost
Attack Type
Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-02T12:17:10.840Z",
  "pubdate": "2026-10-02T12:17:10.840Z",
  "executiveSummary": "This vulnerability is an improper authorization flaw within the Ghost platform, specifically concerning the staff role assignment logic. The vulnerability affects Ghost versions 0.5.0 through 6.63.0. By design, the application fails to enforce granular permission checks when updating staff account roles. An authenticated user possessing the 'Editor' or 'Super Editor' role can exploit this logical oversight to escalate the privileges of lower-privileged users, such as 'Author' or 'Contributor', to match their own elevated role status. The primary impact is unauthorized privilege escalation, which compromises the integrity and confidentiality of the content management system. By promoting users to the Editor or Super Editor level, attackers or malicious insiders can bypass intended organizational hierarchy, gain full control over editorial workflows, and potentially access sensitive configuration settings. The risk is significant as it allows for horizontal and vertical privilege movement within the application's user base without administrative approval. Exploitation requires a valid user account with at least an Editor role and does not necessitate interaction with external systems or complex payloads.",
  "technicalDetails": "The vulnerability originates from a failure in the application's access control layer during the staff management process. Specifically, the API endpoint or backend logic responsible for updating staff member roles fails to validate the requester's authority to assign roles equal to or higher than their own, or to assign roles that they lack the administrative privilege to grant. The system incorrectly trusts the incoming request object when the request is initiated by a user authenticated as an 'Editor' or 'Super Editor'.\nIn a secure implementation, an Editor should be restricted by the Role-Based Access Control (RBAC) model from promoting another user to a role that holds equivalent or superior permissions. The lack of this server-side validation means the application processes the PUT or PATCH request to the staff update endpoint without verifying if the requested role change is authorized for the current user session.\nThe attack flow proceeds as follows: 1) The attacker authenticates into the Ghost administrative panel with valid Editor or Super Editor credentials. 2) The attacker identifies a target user account currently assigned the Author or Contributor role. 3) The attacker intercepts or crafts a request to the staff management API to modify the target user's 'role' attribute. 4) The server processes this request and updates the target user's role to 'Editor' or 'Super Editor' because it fails to perform a cross-check between the requester's session permissions and the role being assigned. 5) Once the target account has been promoted, the attacker can leverage this account to bypass existing limitations, approve their own content, modify administrative settings, or alter other users' information, effectively expanding their footprint within the application.\nThis issue is essentially a Broken Access Control (BAC) vulnerability where the business logic fails to enforce organizational policy. The flaw persists across all versions prior to 6.64.0 because the authorization interceptor is absent or improperly configured for the specific API path handling staff role updates. Post-exploitation, an attacker can maintain persistent administrative access, manipulate site content, and potentially compromise the entire application deployment by utilizing the elevated permissions granted to the manipulated accounts."
}
CVE-2026-104412: Ghost Improper Authorization Privilege Escalation (MEDIUM Severity, CVSS: 4.3) | Sceawere