Reliance on Untrusted Inputs in a Security Decision in Ghost - CVE-2026-103267
Published: September 7, 2026 / Updated: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to create a staff account using an attacker-controlled email address.
The vulnerability exists due to reliance on untrusted inputs in a security decision in the staff invite acceptance process when accepting a staff invitation. A remote user can submit an arbitrary email address with a leaked invite token to create a staff account using an attacker-controlled email address.