CVE-2026-104412: Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment
Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.64.0
Event History
Frequently Asked Questions
Which accounts can exploit this issue, and which users can they promote?
An authenticated user with the Editor or Super Editor role can exploit it. They can assign their own role to Author and Contributor users, promoting those accounts to Editor or Super Editor.
Is authentication required to exploit the vulnerability?
Yes. Exploitation requires an authenticated Editor or Super Editor account; unauthenticated users are not described as able to exploit it.
Which Ghost versions are affected?
Ghost versions from 0.5.0 before 6.64.0 are affected. Updating to 6.64.0 or later removes the affected version range.