CVE-2026-78203: Ghostwriter before 7.1.2 Cross-Client Report Template Disclosure via Unauthorized Template Swap
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a Ghostwriter account with privileges to use the report template swap endpoint. No user interaction is required, and the issue is reachable over the network.
What information could be exposed?
Attackers can attach templates belonging to other clients to reports they control and generate those reports. This can disclose template contents such as letterhead, boilerplate, and methodology text.
Are all Ghostwriter versions affected?
Versions before 7.1.2 are affected. The provided fix reference is commit 5b2a4a297e44c823c16f65b1ba101c742791cd0b.
How would an attacker identify templates from other clients?
The attack relies on sequential template primary keys, which can be enumerated and supplied to the template swap functionality. Successful attachment of a foreign template to an attacker-controlled report indicates exposure.