Sceawere
Vulnerability Detail
CVE-2026-104416UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Admin API Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 11h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- Observable Discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-02T12:17:11.420Z",
"pubdate": "2026-10-02T12:17:11.420Z",
"executiveSummary": "The Ghost platform, spanning versions 4.39.0 through 6.63.x, contains an information disclosure vulnerability within its Admin API.\nThis flaw allows authenticated staff users with standard invite-viewing permissions to access sensitive, secret tokens associated with pending staff invitations.\nBy exposing these tokens, the vulnerability facilitates a critical privilege escalation path; an attacker can intercept these tokens to accept invitations intended for higher-privileged administrative roles.\nThe issue resides in the insufficient access control mechanisms within the API endpoints responsible for managing user invitations.\nSuccessful exploitation allows an adversary to bypass organizational role-based access control (RBAC) policies by assuming the identity and permissions of a higher-privileged user.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the Ghost installation, as it enables unauthorized administrative control over the application environment.\nExploitation requires the attacker to already possess a valid staff account with permission to view existing invites and the presence of at least one pending invitation in the system.",
"technicalDetails": "The vulnerability is rooted in an improper authorization check within the Ghost Admin API, specifically affecting the endpoints used to retrieve or list pending staff invitations.\nThe application fails to verify that the requesting user maintains the appropriate administrative context or role required to view sensitive metadata—specifically the unique invitation tokens—associated with pending staff members.\nAffected versions include all releases from 4.39.0 up to, but not including, 6.64.0.\nThe attack flow begins when an authenticated staff user, who possesses the requisite 'view invites' permission, queries the Admin API for a list of current staff invitations.\nIn the vulnerable state, the API response includes the invitation tokens, which are intended to be accessible only to the system administrator or the recipient of the invite email via a secure channel.\nThe attacker, upon receiving the JSON payload containing these tokens, can leverage the specific token to traverse to the invitation acceptance endpoint.\nBy invoking the acceptance logic with the intercepted secret token, the attacker effectively validates the invitation for an account that may have been configured with higher-privileged roles, such as Owner or Administrator.\nThe system fails to re-validate the requester's authority against the target role associated with the invitation token during the acceptance process, allowing the state transition to succeed.\nConsequently, the attacker is granted elevated privileges within the Ghost instance, providing them with full control over site content, configuration, and user management.\nThe root cause is a failure in the API layer to implement granular access control checks that distinguish between the ability to view the existence of an invite and the ability to access the sensitive authentication secret contained within the invitation entity.\nAs this is an API-level issue, it is accessible via standard HTTP requests once the attacker is authenticated as a legitimate (albeit lower-privileged) staff user.\nThe post-exploitation impact is complete unauthorized privilege escalation, allowing the attacker to bypass the Principle of Least Privilege and potentially compromise the entire site instance."
}