Loading market data...
← Back to CVE feed

CVE-2026-104416

HIGH CVSS 7.5 View on NVD ↗

Description

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Oct 02, 2026 12:17 UTC Modified: Oct 02, 2026 17:59 UTC