Privilege Escalation Vulnerability in Ghost CMS by TryGhost
CVE-2026-105675
7.5HIGH
What is CVE-2026-105675?
In versions 4.39.0 through 6.64.0 of Ghost, a vulnerability existed that allowed staff users with permissions to view staff invites to access secret tokens of pending invites. This exposure could lead to privilege escalation, enabling unauthorized users to accept invites that granted higher-level access than their current roles. The issue was remediated in version 6.64.0, emphasizing the importance of prompt updates to secure the system.
Affected Version(s)
Ghost >= 4.39.0, < 6.64.0
