HIGH 8.5 NVD
CVE-2026-103286
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escal
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-pv24-pfvg-vr83
- https://www.vulncheck.com/advisories/ghost-2.21.0-before-6.56.0-privilege-escalation-via-n
This high severity vulnerability with a CVSS score of 8.5 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.