SB2026090789 - Multiple vulnerabilities in Ghost



SB2026090789 - Multiple vulnerabilities in Ghost

Published: September 7, 2026

Security Bulletin ID SB2026090789
CSH Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 25% Medium 50% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to modify existing member accounts and inject content into newsletters.

The vulnerability exists due to incorrect authorization in Stripe Checkout when processing checkout requests. A remote attacker can attach a paid subscription to an existing member and modify their name to modify existing member accounts and inject content into newsletters.

User interaction is required for malicious newsletter content to be rendered.


2) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: N/A)

CWE-ID: CWE-807 - Reliance on Untrusted Inputs in a Security Decision

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create a staff account using an attacker-controlled email address.

The vulnerability exists due to reliance on untrusted inputs in a security decision in the staff invite acceptance process when accepting a staff invitation. A remote user can submit an arbitrary email address with a leaked invite token to create a staff account using an attacker-controlled email address.


3) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to reactivate a suspended staff account.

The vulnerability exists due to missing authorization in the staff account password-reset functionality when performing a self-service password reset. A remote attacker can reset the password of a suspended staff account to reactivate it.

The impact depends on the original role assigned to the suspended staff account.


4) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose comments and post excerpts for gated content.

The vulnerability exists due to missing authorization in Ghost gated-content comments and post excerpts when handling requests for gated content. A remote attacker can request comments and post excerpts for posts they are not authorized to access to disclose comments and post excerpts for gated content.


Remediation

Install update from vendor's website.