Incorrect authorization in Ghost - #VU151102
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to assign their own role to Author and Contributor users.
The vulnerability exists due to incorrect authorization in Ghost staff user role assignment functionality when assigning roles to staff users. A remote user can assign their own Editor or Super Editor role to Author and Contributor users to assign their own role to Author and Contributor users.