Description
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized account creation
Action: Immediate Patch
AI Analysis

Impact

The staff invitation flow in Ghost contains a race condition that lets many user accounts be created from one invite token. By sending two or more concurrent requests with the same token, an attacker can trigger the account‑creation routine repeatedly. Each resulting account has the privileges granted to the inviting staff member, allowing an attacker to gain unintended accounts and possibly elevate privileges. This is a classic concurrency bug classified by CWE‑362.

Affected Systems

The flaw exists in Ghost CMS version 0.5.0 and every release up to, but not including, 6.23.0. Any organization running those versions is vulnerable; the problem resides in the staff invitation acceptance endpoint of the web API.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, so there is no confirmed public exploitation yet. An adversary would need the ability to issue web requests to the application and must send them almost simultaneously to trigger the race condition. Crafting such a request pattern is straightforward with a small script, meaning an attacker can engineer the attack quickly. Although it does not lead to remote code execution, it provides unauthorized account creation and can aid in privilege escalation.

Generated by OpenCVE AI on October 1, 2026 at 14:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.23.0 or later, which removes the race condition.
  • If an upgrade is unavailable, temporarily disable the invitation acceptance endpoint or add a server‑side lock to serialize requests and prevent simultaneous processing of the same token.
  • After taking action, review the user table for duplicate accounts that may have been created and delete or merge them.

Generated by OpenCVE AI on October 1, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.
Title Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-362
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T14:40:36.318Z

Reserved: 2026-09-30T10:59:00.639Z

Link: CVE-2026-103282

cve-icon Vulnrichment

Updated: 2026-10-01T14:40:33.116Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:24.240

Modified: 2026-10-01T15:17:27.233

Link: CVE-2026-103282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')