CVE-2026-104416
Received Received - Intake

Ghost Admin API Information Disclosure via Pending Staff Invites

Vulnerability report for CVE-2026-104416, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tryghost ghost From 4.39.0 (inc) to 6.64.0 (exc)
ghost ghost to 6.64.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104416 is an information disclosure vulnerability in Ghost versions 4.39.0 to 6.64.0. It allows staff users with invite viewing permission to see secret tokens of pending staff invites, including those for higher-privileged roles. This enables privilege escalation by accepting pending invites for elevated access.

Detection Guidance

To detect this vulnerability, check Ghost versions between 4.39.0 and 6.63.0. Use commands like 'ghost version' for CLI or inspect Docker image tags. Review Admin API logs for unusual invite token access patterns. Verify staff user permissions for invite viewing access.

Impact Analysis

If you are a Ghost user running a vulnerable version, an attacker with staff access could exploit this to escalate their privileges. This could lead to unauthorized access to sensitive data, control over the Ghost instance, or further compromise of the system hosting Ghost.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face compliance breaches, legal penalties, or reputational damage if exploited.

Mitigation Strategies

Immediately update Ghost to version 6.64.0 or later using Docker or Ghost-CLI. Remove unnecessary staff user permissions, especially invite viewing access. Monitor for unauthorized privilege escalation attempts and rotate all staff invite tokens as a precaution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104416. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart