{"api_version":"1","generated_at":"2026-10-05T21:53:45+00:00","cve":"CVE-2026-105678","urls":{"html":"https://cve.report/CVE-2026-105678","api":"https://cve.report/api/cve/CVE-2026-105678.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-105678","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-105678"},"summary":{"title":"Ghost: Editors Could Promote Staff Users to Their Own Role","description":"Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-10-05 20:17:14","updated_at":"2026-10-05 20:17:14"},"problem_types":["CWE-269","CWE-863","CWE-269 CWE-269: Improper Privilege Management","CWE-863 CWE-863: Incorrect Authorization"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/TryGhost/Ghost/releases/tag/v6.64.0","name":"https://github.com/TryGhost/Ghost/releases/tag/v6.64.0","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/TryGhost/Ghost/commit/99c5642b9bb481df4811a004a6f19d6143ed9aaf","name":"https://github.com/TryGhost/Ghost/commit/99c5642b9bb481df4811a004a6f19d6143ed9aaf","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/TryGhost/Ghost/issues/30764","name":"https://github.com/TryGhost/Ghost/issues/30764","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc","name":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-105678","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105678","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"TryGhost","product":"Ghost","version":"affected >= 0.5.0, < 6.64.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"Ghost","vendor":"TryGhost","versions":[{"status":"affected","version":">= 0.5.0, < 6.64.0"}]}],"descriptions":[{"lang":"en","value":"Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-05T19:20:36.210Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc"},{"name":"https://github.com/TryGhost/Ghost/issues/30764","tags":["x_refsource_MISC"],"url":"https://github.com/TryGhost/Ghost/issues/30764"},{"name":"https://github.com/TryGhost/Ghost/commit/99c5642b9bb481df4811a004a6f19d6143ed9aaf","tags":["x_refsource_MISC"],"url":"https://github.com/TryGhost/Ghost/commit/99c5642b9bb481df4811a004a6f19d6143ed9aaf"},{"name":"https://github.com/TryGhost/Ghost/releases/tag/v6.64.0","tags":["x_refsource_MISC"],"url":"https://github.com/TryGhost/Ghost/releases/tag/v6.64.0"}],"source":{"advisory":"GHSA-4pvx-fwjj-8gpc","discovery":"UNKNOWN"},"title":"Ghost: Editors Could Promote Staff Users to Their Own Role"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-105678","datePublished":"2026-10-05T19:20:36.210Z","dateReserved":"2026-10-05T17:48:58.626Z","dateUpdated":"2026-10-05T19:20:36.210Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-05 20:17:14","lastModifiedDate":"2026-10-05 20:17:14","problem_types":["CWE-269","CWE-863","CWE-269 CWE-269: Improper Privilege Management","CWE-863 CWE-863: Incorrect Authorization"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"105678","Ordinal":"1","Title":"Ghost: Editors Could Promote Staff Users to Their Own Role","CVE":"CVE-2026-105678","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"105678","Ordinal":"1","NoteData":"Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.","Type":"Description","Title":"Ghost: Editors Could Promote Staff Users to Their Own Role"}]}}}