Sceawere

Vulnerability Detail

CVE-2026-105678UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Unauthorized Role Assignment Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-269: Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-05T20:17:14.913Z",
  "pubdate": "2026-10-05T20:17:14.913Z",
  "executiveSummary": "This vulnerability is an Improper Access Control flaw within the Ghost Node.js content management system. The issue arises from a failure in the application's authorization logic, which incorrectly permits users with Editor or Super Editor roles to assign unauthorized roles—specifically Author or Contributor—to other existing users.\nThis flaw grants privileged users the ability to modify the permission structures of lower-privileged accounts, potentially allowing for internal permission manipulation that exceeds the scope of their assigned security profiles. The vulnerability affects Ghost versions 0.5.0 through 6.64.0.\nThe risk is primarily internal, as the attacker must already possess an authenticated Editor or Super Editor session. By exploiting this authorization gap, an attacker can bypass the principle of least privilege, escalating or de-escalating the account status of other users within the system. This capability poses a significant risk to administrative integrity and role-based access control (RBAC) enforcement, potentially leading to unauthorized data access or modification by manipulated accounts.\nThere are no requirements for external network access beyond having authenticated administrative privileges within the Ghost management interface. The vulnerability is fully remediated in version 6.64.0.",
  "technicalDetails": "The vulnerability resides within the user management module of the Ghost CMS, specifically within the role assignment logic governing user metadata modification. The root cause is a failure to properly validate the authorization scope of the actor during an update request for a target user's role attribute.\nIn the affected versions (0.5.0 to 6.64.0), the backend API failed to enforce strict access control checks when an authenticated user with an 'Editor' or 'Super Editor' role initiated a PUT or PATCH request to modify the profile of another user. While these roles are intended to manage content, the application logic failed to verify whether the assigned role being granted to the target user was permitted under the requestor's current authorization matrix.\nThe attack flow proceeds as follows: 1. The attacker authenticates as a user with an 'Editor' or 'Super Editor' role. 2. The attacker identifies the User ID of a target user (e.g., an existing 'Author' or 'Contributor'). 3. The attacker crafts an API request to the endpoint responsible for user management, typically involving a change to the user's role field in the JSON payload. 4. Due to the lack of server-side validation against the requestor's capabilities versus the requested role assignment, the application updates the database record for the target user to the specified role, despite the editor lacking the explicit privilege to assign that specific role level.\nBecause the server-side code does not perform an effective check on the 'role' parameter during the account update process, it assumes that any user with administrative-style access to the management console has full authority over user roles. This allows for the manipulation of user hierarchies, effectively circumventing the intended RBAC model defined by the Ghost platform.\nThe impact is a compromise of the integrity of the user authorization system. An attacker can leverage this to demote authorized users or manipulate account permissions, creating a scenario where administrative control is undermined. This is a logic-based vulnerability that does not require memory corruption or injection, but rather exploits the gap between the intended security policy and the actual code execution path during user object updates."
}
CVE-2026-105678: Ghost Unauthorized Role Assignment Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere