Impact
Ghost versions from 2.21.0 up through 6.55.x contain a privilege escalation flaw in the notifications subsystem. The bug allows users who have only low‑privilege staff accounts to obtain higher‑privilege staff roles without any authorization checks. This is a classic privilege escalation issue (CWE‑266). The impact is that an attacker who can perform actions as a harmless staff member can later manage or publish content that potentially compromising content integrity and platform security.
Affected Systems
TryGhost's Ghost content‑management system with versions 2.21.0, 2.22.0, 3.x, 4.x, 5.x, and all builds of 6.0 through 6.55.x are affected. Users who have installed any of these releases are at risk if they still run low‑privilege staff accounts that can interact with the notification feature. The issue does not affect Ghost versions 6.56.0 and newer.
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑severity flaw that can lead to unauthorized access to editorial and administrative functions. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from public data, but the weakness is listed in CISA's KEV catalogue as not present, suggesting no known active exploit. The vulnerability can only be exploited by users who already have low‑privilege staff access, so its reach is limited to existing staff accounts. Nevertheless, once an attacker gains elevated staff roles, the full range of Ghost's administrative capabilities becomes available to them.
OpenCVE Enrichment