Sceawere

Vulnerability Detail

CVE-2026-105675UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Privilege Escalation via Invites

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-203: Observable Discrepancy
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting a pending invite. This issue is fixed in version 6.64.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-05T20:17:14.367Z",
  "pubdate": "2026-10-05T20:17:14.367Z",
  "executiveSummary": "A privilege escalation vulnerability exists in Ghost, a Node.js content management system, stemming from improper access control in the staff invite management module.\nThe vulnerability allows a staff user with restricted permissions to access the secret tokens of pending invitations intended for other users, including those with higher-level administrative privileges.\nBy capturing these secret tokens, an authenticated attacker can perform an account takeover or escalate their internal role by accepting the pending invitations.\nThe flaw affects versions 4.39.0 through 6.64.0 and poses a significant risk to the integrity and confidentiality of the administrative backend.\nSuccessful exploitation requires the attacker to hold an existing staff account on the Ghost instance and possess the 'view staff invites' permission.\nThe vulnerability is primarily rooted in an authorization bypass where the application fails to validate the scope of the requester against the privilege level of the invite being retrieved.\nThe impact includes unauthorized elevation of privileges, potential full system compromise, and unauthorized administrative actions within the Ghost instance.\nDefensive posture requires immediate patching to the fixed version 6.64.0.",
  "technicalDetails": "The vulnerability is categorized as an Insecure Direct Object Reference (IDOR) combined with improper authorization checks within the Ghost invite management API.\nThe root cause lies in the application's backend logic for processing requests related to pending staff invitations. Specifically, the API endpoint responsible for listing or retrieving invitation details fails to adequately verify if the requesting user has the appropriate authorization level to view specific, high-privilege invite metadata.\nAffected versions include any deployment of Ghost from 4.39.0 up to and including 6.64.0.\nThe attack flow begins when an authenticated staff member, who already possesses the legitimate permission to view the staff invite list, executes a query to the backend API to retrieve pending invitations. Because the backend fails to apply strict Role-Based Access Control (RBAC) filtering on the response object, the API returns the sensitive 'secret token' associated with every pending invitation, regardless of the role designated for that invite.\nAn attacker can monitor the API response for invitations directed toward administrative or 'Owner' roles. Upon discovering a token for a high-privilege invite, the attacker can then invoke the invitation acceptance flow provided by the Ghost application, typically handled via a specific endpoint that consumes the secret token to bind an account or upgrade an existing profile.\nBy submitting the discovered secret token, the attacker validates their identity against the invitation parameters. If successful, the system updates the attacker's account privileges to match those defined in the captured invitation. This effectively bypasses the intended separation of duties and access control policies established by the Ghost administrator.\nThis vulnerability is particularly dangerous because the API exposure provides an attacker with the necessary credentials (the secret token) to bypass standard authentication workflows, allowing for persistent privilege escalation. Post-exploitation, the attacker gains the operational capabilities associated with the elevated role, which may include site configuration, user management, and content deletion, depending on the role obtained via the intercepted invite.\nThe lack of server-side validation during the retrieval of invitation data allows the information disclosure of tokens that should otherwise remain private until the intended recipient interacts with the invite link via a secure channel."
}
CVE-2026-105675: Ghost Privilege Escalation via Invites (HIGH Severity, CVSS: 7.5) | Sceawere