CVE-2026-104412

medium

Description

Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.

References

https://www.vulncheck.com/advisories/ghost-0.5.0-before-6.64.0-privilege-escalation-via-staff-role-assignment

https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91423

Details

Source: Mitre, NVD

Published: 2026-10-02

Updated: 2026-10-02

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00192