CVE-2026-103286: Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.56.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Ghost installations running versions from 2.21.0 up to, but not including, 6.56.0 are affected. Exploitation requires that an attacker already has a low-privilege staff account.
Can an unauthenticated internet attacker exploit this issue?
No. The vulnerability requires low-privilege staff access and user interaction, as reflected by the PR:L and UI:R vector components.
What privileges could an attacker gain?
A low-privilege staff user can exploit the notifications system to obtain a higher-privilege staff role because authorization checks are insufficient.
What is the remediation version?
Upgrade Ghost to version 6.56.0 or later. The affected range ends before 6.56.0.