CVE-2026-103267
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TryGhost | Ghost | 0.5.0 < 6.62.0 | affected |
| TryGhost | Ghost | 6.62.0 | unaffected |
Weaknesses
- CWE-807: Reliance on Untrusted Inputs in a Security Decision
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-xcgh-2828-cvmx
- https://www.vulncheck.com/advisories/ghost-0.5.0-before-6.62.0-arbitrary-email-registration-via-staff-invite
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.