CVE-2026-103267 PUBLISHED

Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite

Assigner: VulnCheck
Reserved: 30.09.2026 Published: 01.10.2026 Updated: 01.10.2026

Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor TryGhost
Product Ghost
Versions Default: unaffected
  • affected from 0.5.0 to 6.62.0 (excl.)
  • Version 6.62.0 is unaffected

Credits

  • unknownhad reporter
  • doanmanhducz reporter
  • EclipsSec reporter

References

Problem Types

  • Reliance on Untrusted Inputs in a Security Decision CWE