CVE-2026-105678: Ghost: Editors Could Promote Staff Users to Their Own Role
Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.64.0
Event History
Frequently Asked Questions
Which users can exploit this issue?
Authenticated staff users assigned the Editor or Super Editor role can exploit it. They can assign their own role to users who currently have the Author or Contributor role.
What is the practical impact of exploitation?
An Editor or Super Editor can improperly elevate an Author or Contributor to the same role as the attacker. The provided data identifies an integrity impact, but does not describe confidentiality or availability impact.
Which Ghost versions need remediation?
Ghost versions from 0.5.0 through versions before 6.64.0 are affected. Upgrade to version 6.64.0, which fixes the issue.
How can I assess whether my instance may have been affected?
Review role-assignment changes involving Editor or Super Editor accounts, especially cases where those accounts assigned their own role to Author or Contributor users. The provided information does not specify available audit-log fields or detection indicators.