Description
Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.
Published: 2026-10-02
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Information Disclosure & Privilege Escalation
Action: Patch
AI Analysis

Impact

Ghost CMS versions 4.39.0 through 6.63.9 contain an information disclosure flaw in the Admin API that lets authorized staff see the secret tokens attached to pending staff invites. By obtaining these tokens, a staff user can accept an invitation designed for a higher‑privileged role, thereby elevating their own privileges. The root weakness is an improper access control that allows staff users to view data they should not have access to, classified under CWE‑203.

Affected Systems

Affected is Ghost CMS from TryGhost, specifically any deployment running Ghost 4.39.0, 5.x, or 6.x up to 6.63.9. These versions expose the Admin API endpoint that leaks invite tokens to any staff member with invite‑view permission.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.7, indicating high severity, but the EPSS score is not available so the exploitation probability cannot be quantified at this time. It is not listed in the CISA KEV catalog. The likely attack vector is an authenticated request to the Admin API endpoint made by a staff user with the appropriate permission; the attacker does not need to bypass authentication but merely requires the right privilege level to trigger the disclosure.

Generated by OpenCVE AI on October 2, 2026 at 13:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost CMS to version 6.64.0 or later, which fixes the invite token disclosure in the Admin API.
  • If an upgrade cannot be applied immediately, remove or restrict staff users’ permission to view pending invites until the patch is applied.
  • Conduct a role audit and adjust staff permissions so that only necessary users can view pending invites, ensuring least privilege.

Generated by OpenCVE AI on October 2, 2026 at 13:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.
Title Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-203
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:37:59.003Z

Reserved: 2026-10-02T00:44:44.529Z

Link: CVE-2026-104416

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:11.420

Modified: 2026-10-02T12:17:11.420

Link: CVE-2026-104416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:15:16Z

Weaknesses