CVE-2026-104416

high

Description

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

References

https://www.vulncheck.com/advisories/ghost-4.39.0-before-6.64.0-invite-token-disclosure-via-admin-api

https://github.com/TryGhost/Ghost/security/advisories/GHSA-v6q3-xqxm-6f5v

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91427

Details

Source: Mitre, NVD

Published: 2026-10-02

Updated: 2026-10-02

Risk Information

CVSS v2

Base Score: 7.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 7.7

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00308