CVE-2026-104416 PUBLISHED

Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor TryGhost
Product Ghost
Versions Default: unaffected
  • affected from 4.39.0 to 6.64.0 (excl.)
  • Version 6.64.0 is unaffected

Credits

  • nhattanhh reporter

References

Problem Types

  • Observable Discrepancy CWE