Description
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
Published: 2026-10-01
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

Ghost versions from 2.21.0 up through 6.55.x contain a privilege escalation flaw in the notifications subsystem. The bug allows users who have only low‑privilege staff accounts to obtain higher‑privilege staff roles without any authorization checks. This is a classic privilege escalation issue (CWE‑266). The impact is that an attacker who can perform actions as a harmless staff member can later manage or publish content that potentially compromising content integrity and platform security.

Affected Systems

TryGhost's Ghost content‑management system with versions 2.21.0, 2.22.0, 3.x, 4.x, 5.x, and all builds of 6.0 through 6.55.x are affected. Users who have installed any of these releases are at risk if they still run low‑privilege staff accounts that can interact with the notification feature. The issue does not affect Ghost versions 6.56.0 and newer.

Risk and Exploitability

The CVSS score of 8.5 indicates a high‑severity flaw that can lead to unauthorized access to editorial and administrative functions. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from public data, but the weakness is listed in CISA's KEV catalogue as not present, suggesting no known active exploit. The vulnerability can only be exploited by users who already have low‑privilege staff access, so its reach is limited to existing staff accounts. Nevertheless, once an attacker gains elevated staff roles, the full range of Ghost's administrative capabilities becomes available to them.

Generated by OpenCVE AI on October 1, 2026 at 14:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.56.0 or later to eliminate the vulnerability.
  • Revoke or downgrade low‑privilege staff roles and disable the notifications feature for those accounts until the upgrade is applied.
  • Review all staff permissions to enforce the least‑privilege principle and ensure no low‑privilege accounts retain notification access.

Generated by OpenCVE AI on October 1, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
Title Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-266
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:30:38.273Z

Reserved: 2026-09-30T10:59:26.443Z

Link: CVE-2026-103286

cve-icon Vulnrichment

Updated: 2026-10-01T15:30:23.118Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:24.880

Modified: 2026-10-01T16:17:35.880

Link: CVE-2026-103286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:15:10Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment