CVE-2026-103286: Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications

Published Oct 1, 2026
·
Updated

Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.

Affected Software

1 affected component
Ghost Ghost>=2.21.0<6.56.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Ghost to a version that resolves this vulnerability.

    Fixed in 6.56.0

Event History

Oct 1, 2026
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Ghost installations running versions from 2.21.0 up to, but not including, 6.56.0 are affected. Exploitation requires that an attacker already has a low-privilege staff account.

2

Can an unauthenticated internet attacker exploit this issue?

No. The vulnerability requires low-privilege staff access and user interaction, as reflected by the PR:L and UI:R vector components.

3

What privileges could an attacker gain?

A low-privilege staff user can exploit the notifications system to obtain a higher-privilege staff role because authorization checks are insufficient.

4

What is the remediation version?

Upgrade Ghost to version 6.56.0 or later. The affected range ends before 6.56.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203