Authorization Flaw in Ghost Node.js CMS by TryGhost
CVE-2026-105680
6.5MEDIUM
What is CVE-2026-105680?
The Ghost CMS, a popular Node.js content management system, contained an authorization error that permitted users with the Author role to delete articles and pages that they did not create. This vulnerability existed in versions 5.81.0 through 6.60.0 and was remedied in version 6.60.0. Maintain secure user roles and update your Ghost installation to the latest version to safeguard against this kind of vulnerability.
Affected Version(s)
Ghost >= 5.81.0, < 6.60.0
