MEDIUM 5.3 NVD
CVE-2026-104412
Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to oth
Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc
- https://www.vulncheck.com/advisories/ghost-0.5.0-before-6.64.0-privilege-escalation-via-st
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.