CVE-2026-103267
Received Received - Intake

Authentication Bypass in Ghost Staff Invite Acceptance

Vulnerability report for CVE-2026-103267, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ghost ghost to 6.62.0 (exc)
tryghost ghost to 6.62.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-807 The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Ghost versions before 6.62.0 have an authentication bypass flaw where users can register with any email address when accepting staff invites. This happens because the system does not properly validate email addresses during invite acceptance, allowing attackers to use arbitrary emails or legitimate users to register with unintended providers.

Detection Guidance

To detect this vulnerability, check Ghost versions before 6.62.0 by running commands like 'ghost version' in the Ghost CLI or inspecting Docker container versions. Look for unauthorized account creations with unexpected email domains in logs.

Impact Analysis

Attackers could exploit this to gain unauthorized access by accepting leaked invite tokens with their own email addresses. Legitimate users might accidentally register with incorrect email providers, leading to confusion or loss of access to their accounts.

Mitigation Strategies

Immediately update Ghost to version 6.62.0 or later using Ghost-CLI or Docker. Review recent account registrations for suspicious email addresses and revoke unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103267. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart