CVE-2026-105680
Received Received - Intake

Ghost CMS Staff Author Role Post Deletion Vulnerability

Vulnerability report for CVE-2026-105680, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 5.81.0, < 6.60.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ghost CMS allowed users with the Author role to delete posts and pages they did not author. The issue existed between versions 5.81.0 and 6.60.0 due to improper permission checks during deletion operations. The system failed to verify ownership, allowing authors to delete content they did not create.

Detection Guidance

To detect this vulnerability, check Ghost CMS versions between 5.81.0 and 6.60.0. Use commands like 'ghost version' to verify the installed version. Review logs for unauthorized post deletions by authors. Check if authors can delete posts they do not own by testing deletion permissions in the admin panel.

Impact Analysis

An attacker with Author role access could delete important posts or pages, disrupting content availability. This could lead to data loss, reputational damage, or operational disruption if critical content is removed without authorization.

Compliance Impact

This vulnerability could violate compliance requirements that mandate proper access controls and data integrity, such as GDPR's data protection principles or HIPAA's security rules. Unauthorized deletion of content may result in non-compliance penalties or data breaches.

Mitigation Strategies

Upgrade Ghost CMS to version 6.60.0 or later immediately. Apply the patch from the security fix commit cf2f718a67faa342c27989b701554ddd63862165. Review and restrict author permissions to prevent unauthorized deletions. Monitor logs for suspicious deletion activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105680. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart