Description
Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Ghost CMS incorrectly restricts staff role assignments, allowing a user with Editor or Super Editor role to assign those same or higher roles to other staff members, even though the user does not possess the permission to do so. The primary impact is the unauthorized elevation of privileges, which can enable an attacker to gain administrative or editorial control over the site, modify content, and potentially access sensitive data or configuration settings. This flaw falls under CWE‑269, Improper Privilege Management, and can lead to a moderate‑severity compromise of confidentiality, integrity, and availability within the affected system.

Affected Systems

The vulnerable product is Ghost, the open‑source blogging platform sold under TryGhost:Ghost. All releases from Ghost 0.5.0 through 6.63.9 (i.e., any version prior to 6.64.0) are affected. The vulnerability is specific to the staff role assignment functionality within these releases.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalogue, suggesting that there is no known widespread exploitation at the time of this analysis. The exploit requires an authenticated account with Editor or Super Editor privileges; the attacker then abuses the lax role‑assignment check to elevate their own privileges or those of other staff users. Because the attack vector is internal and requires legitimate credentials, the risk is primarily confined to organizations that grant these roles without adequate oversight. Nonetheless, the ability to silently promote users to higher roles can be leveraged for broader attacks such as site takeover or persistent misuse of administrative privileges.

Generated by OpenCVE AI on October 2, 2026 at 12:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.64.0 or later, which corrects the role‑assignment validation logic.
  • If an immediate upgrade is not possible, remove the Editor and Super Editor roles from all users who do not require them and restrict role creation to administrators only.
  • Audit current staff role assignments that have been promoted by existing Editors or Super Editors and revoke any unintended escalations before proceeding with a system-wide upgrade.

Generated by OpenCVE AI on October 2, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.
Title Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-269
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:37:56.456Z

Reserved: 2026-10-02T00:44:44.528Z

Link: CVE-2026-104412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:10.840

Modified: 2026-10-02T12:17:10.840

Link: CVE-2026-104412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:00:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management