CVE-2026-105678

Source
https://cve.org/CVERecord?id=CVE-2026-105678
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105678.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105678
Aliases
Published
2026-10-05T19:20:36Z
Modified
2026-10-07T02:45:57Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Ghost: Editors Could Promote Staff Users to Their Own Role
Details

Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-269",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105678.json"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.5.0"
        },
        {
            "fixed": "6.64.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105678.json"