---
id: CVE-2026-104412
title: >-
  Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment,
  allowing users with the Editor or Super Editor role to assign their own role
  to other staff despite lacking permission to do so
summary: >-
  Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment,
  allowing users with the Editor or Super Editor role to assign their own role
  to other staff despite lacking permission to do so. An authenticated Editor or
  Supe…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-269
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 0.5.0 < 6.64.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:10.840'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104412'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-4pvx-fwjj-8gpc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-0.5.0-before-6.64.0-privilege-escalation-via-staff-role-assignment
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.326Z'
---

## Overview

Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
