CVE-2026-78203
Received Received - Intake

Ghostwriter Template Ownership Validation Flaw Leads to Report Data Exposure

Vulnerability report for CVE-2026-78203, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: VulnCheck

Description

Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
specterops ghostwriter to 7.1.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78203 is a vulnerability in Ghostwriter versions before 7.1.2 where the report template swap endpoint fails to validate template ownership. Attackers can exploit sequential template primary keys to attach client-scoped templates from other clients to their own reports. This allows them to generate reports and disclose sensitive template contents like letterhead, boilerplate, and methodology text.

Detection Guidance

To detect CVE-2026-78203, check Ghostwriter version with: pip show ghostwriter. If version is below 7.1.2, the system is vulnerable. Review logs for unauthorized template swaps or report generation events involving templates from other clients.

Impact Analysis

An attacker with low privileges could access proprietary template content from other clients, leading to confidentiality breaches. Sensitive data like branding, methodologies, and boilerplate text may be exposed. Unauthorized template swaps could also allow tampering with report content or metadata.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized disclosure of sensitive client data. GDPR requires protecting personal data, while HIPAA mandates safeguarding protected health information. Template content may contain such data, and its exposure violates these regulations.

Mitigation Strategies

Upgrade Ghostwriter to version 7.1.2 or later immediately. Review user permissions to ensure only authorized users can access or modify templates. Monitor for suspicious activities like unauthorized template attachments or report generation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78203. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart