Sceawere

Vulnerability Detail

CVE-2026-105680UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Insecure Author Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1h ago
Vendor
TryGhost
Product
Ghost
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T20:17:15.903Z",
  "pubdate": "2026-10-05T20:17:15.903Z",
  "executiveSummary": "A broken access control vulnerability exists in the Ghost content management system, allowing users with the Author role to perform unauthorized delete operations on content they do not own.\nThe vulnerability affects Ghost versions 5.81.0 through 6.59.x. By exploiting this flaw, an authenticated user with restricted privileges can circumvent internal permission checks to delete posts and pages authored by other users, including administrators.\nThe root cause is a failure in the application's authorization logic, which fails to properly validate content ownership before executing delete requests. This represents a significant risk to data integrity and availability, as malicious or compromised Author accounts can perform mass data destruction without elevated administrative privileges.\nExploitation requires a valid, authenticated session with the 'Author' role. No specialized network access beyond standard application reachability is required, as the vulnerability resides within the backend API logic handling resource management.",
  "technicalDetails": "The vulnerability is identified as a broken access control issue originating from the application's resource management controller. Within the Ghost architecture, the API responsible for processing delete requests for posts and pages failed to implement server-side validation to verify that the requesting user's identity matched the author_id of the target resource.\nIn Ghost's permission model, the 'Author' role is intended to have restricted access, typically limited to CRUD operations on content created by that specific user. However, the affected versions failed to enforce this constraint during the deletion workflow. When an authenticated 'Author' submits a delete request—typically an HTTP DELETE method targeting the resource endpoint /ghost/api/admin/posts/{id}/—the application processes the request based on the user's authenticated session state but fails to perform an ownership check against the database record for the specified {id}.\nThe attack flow follows a straightforward process: first, an attacker must authenticate as a user with the 'Author' role. Second, the attacker discovers or guesses the resource ID of a target post or page not owned by them. Third, the attacker initiates a delete request to the API. Because the backend logic lacks an access control list (ACL) check or an ownership verification function (e.g., 'if current_user.id != resource.author_id: deny_access'), the system proceeds to trigger the deletion logic in the database abstraction layer.\nThe vulnerable component is the post-management API controller. The flaw exists due to an oversight in the middleware or business logic layer that handles resource authorization. Because the application processes these requests assuming the caller is authorized for the target resource based solely on the active session, it bypasses intended security boundaries. Post-exploitation impact is limited to unauthorized data destruction (denial of service against content availability), as the flaw does not inherently grant elevated permissions or facilitate remote code execution. However, the integrity impact is severe, as it permits the deletion of site-critical content by low-privilege accounts."
}
CVE-2026-105680: Ghost Insecure Author Access Control (MEDIUM Severity, CVSS: 6.5) | Sceawere