CVE-2026-78203: Ghostwriter before 7.1.2 Cross-Client Report Template Disclosure via Unauthorized Template Swap

Published Aug 24, 2026
·
Updated

Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text.

Affected Software

1 affected component
Ghostwriter Ghostwriter<7.1.2

Event History

Aug 24, 2026
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs a Ghostwriter account with privileges to use the report template swap endpoint. No user interaction is required, and the issue is reachable over the network.

2

What information could be exposed?

Attackers can attach templates belonging to other clients to reports they control and generate those reports. This can disclose template contents such as letterhead, boilerplate, and methodology text.

3

Are all Ghostwriter versions affected?

Versions before 7.1.2 are affected. The provided fix reference is commit 5b2a4a297e44c823c16f65b1ba101c742791cd0b.

4

How would an attacker identify templates from other clients?

The attack relies on sequential template primary keys, which can be enumerated and supplied to the template swap functionality. Successful attachment of a foreign template to an attacker-controlled report indicates exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203