Incorrect authorization in Ghost - #VU151102

 

Incorrect authorization in Ghost - #VU151102

Published: September 18, 2026


Vulnerability identifier: #VU151102
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to assign their own role to Author and Contributor users.

The vulnerability exists due to incorrect authorization in Ghost staff user role assignment functionality when assigning roles to staff users. A remote user can assign their own Editor or Super Editor role to Author and Contributor users to assign their own role to Author and Contributor users.


Affected software

Ghost

Remediation

Install security update from vendor's website.

Ghost - update to 6.64.0

External References

Related Security Bulletins