HIGH 7.7 NVD
CVE-2026-104416
Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff
Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-v6q3-xqxm-6f5v
- https://www.vulncheck.com/advisories/ghost-4.39.0-before-6.64.0-invite-token-disclosure-vi
This high severity vulnerability with a CVSS score of 7.7 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.