Description
Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Upgrade
AI Analysis

Impact

Ghost versions prior to 6.62.0 allow users to specify an arbitrary email address when accepting a staff invite, effectively bypassing the intended invitation flow. This flaw enables attackers who have acquired leaked invite tokens to create accounts with any chosen email address, or it allows legitimate invitees to end up registered with an unintended email provider. The result is unauthorized access to the application with staff or administrative privileges, exposing the system to potential data theft, manipulation, or further compromise. This weakness aligns with CWE-807, a failure to enforce proper permission checks during authentication.

Affected Systems

The vulnerability affects Ghost deployments by TryGhost. All Ghost releases before 6.62.0, including the 0.5.0 release, are impacted. Users running these older versions are at risk until they update to a patched release.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, but the absence of an EPSS score suggests that widespread exploitation is not yet documented. The vulnerability is not included in CISA’s KEV catalog. Attackers would need a valid staff invite token, which may be leaked or compromised, and can then execute the bypass from a remote web interface. Because the flaw allows direct account creation without legitimate verification, the impact is significant for the scopes that rely on staff invites for privileged access.

Generated by OpenCVE AI on October 1, 2026 at 14:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.62.0 or later, which removes the arbitrary email registration flaw.
  • Disable or restrict the staff invite acceptance process so that only preapproved or verified email addresses can be used, or enable email verification for new accounts.
  • Audit and revoke any leaked or potentially compromised staff invite tokens, and monitor account registrations for suspicious activity while the patch is pending.

Generated by OpenCVE AI on October 1, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.
Title Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-807
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T16:37:02.408Z

Reserved: 2026-09-30T10:58:33.573Z

Link: CVE-2026-103267

cve-icon Vulnrichment

Updated: 2026-10-01T16:36:55.415Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:21.900

Modified: 2026-10-01T17:17:18.193

Link: CVE-2026-103267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:45:09Z

Weaknesses
  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision