Sceawere
Vulnerability Detail
CVE-2026-78203UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghostwriter Template Ownership Validation Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 2h ago
- Vendor
- GhostManager
- Product
- Ghostwriter
- Attack Type
- Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-08-24T01:16:57.530Z",
"pubdate": "2026-08-24T01:16:57.530Z",
"executiveSummary": "An authorization vulnerability exists in Ghostwriter before version 7.1.2 within the report template swap endpoint, specifically related to the failure to validate template ownership.\nThis flaw allows unauthorized attackers to attach client-scoped templates belonging to different clients to their own reports.\nThe primary impact of this vulnerability is the unauthorized disclosure of sensitive proprietary information, including letterhead, boilerplate text, and internal methodology text embedded within the targeted templates.\nThe affected product is Ghostwriter in versions prior to 7.1.2.\nThe risk implications include unauthorized access to confidential client data and intellectual property residing in cross-client report templates.\nAttacker capabilities involve the enumeration of sequential template primary keys to identify and attach foreign templates to unauthorized report structures.\nExploitation requirements include the ability to interact with the report template swap endpoint and leverage predictable or sequential primary keys to access out-of-scope template resources.",
"technicalDetails": "The vulnerability stems from an insecure direct object reference or missing access control check within the report template swap endpoint of Ghostwriter before version 7.1.2.\nThe vulnerable component fails to enforce proper authorization boundaries to verify whether the authenticated user or the target report's client scope matches the ownership of the requested template.\nGhostwriter utilizes sequential primary keys for database records, which introduces a critical vector for enumeration.\nThe attack flow proceeds as follows: First, an attacker interacts with the report template swap endpoint. Second, the attacker leverages the predictable sequential nature of template primary keys to systematically probe and enumerate templates belonging to other clients or organizations within the system.\nThird, upon identifying valid primary keys associated with foreign, client-scoped templates, the attacker exploits the lack of ownership validation to successfully attach these unauthorized templates to their own reports.\nFinally, the attacker triggers the report generation functionality to compile the report containing the newly attached foreign templates.\nThis post-exploitation phase results in the complete disclosure of sensitive template contents, which may encompass proprietary letterhead graphics or structures, confidential boilerplate clauses, and proprietary assessment methodology text.\nThe vulnerability affects Ghostwriter deployments running versions prior to 7.1.2, requiring network access to the application endpoint and standard user-level interaction depending on authentication boundaries, though the core issue resides in server-side authorization enforcement."
}