SB2026090789 - Multiple vulnerabilities in Ghost
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to modify existing member accounts and inject content into newsletters.
The vulnerability exists due to incorrect authorization in Stripe Checkout when processing checkout requests. A remote attacker can attach a paid subscription to an existing member and modify their name to modify existing member accounts and inject content into newsletters.
User interaction is required for malicious newsletter content to be rendered.
2) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: N/A)
CWE-ID: CWE-807 - Reliance on Untrusted Inputs in a Security Decision
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to create a staff account using an attacker-controlled email address.
The vulnerability exists due to reliance on untrusted inputs in a security decision in the staff invite acceptance process when accepting a staff invitation. A remote user can submit an arbitrary email address with a leaked invite token to create a staff account using an attacker-controlled email address.
3) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to reactivate a suspended staff account.
The vulnerability exists due to missing authorization in the staff account password-reset functionality when performing a self-service password reset. A remote attacker can reset the password of a suspended staff account to reactivate it.
The impact depends on the original role assigned to the suspended staff account.
4) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose comments and post excerpts for gated content.
The vulnerability exists due to missing authorization in Ghost gated-content comments and post excerpts when handling requests for gated content. A remote attacker can request comments and post excerpts for posts they are not authorized to access to disclose comments and post excerpts for gated content.
Remediation
Install update from vendor's website.