---
id: CVE-2026-104416
title: >-
  Ghost from 4.39.0 before 6.64.0 contains an information disclosure
  vulnerability in the Admin API that allows staff users to view secret tokens
  of pending staff invites
summary: >-
  Ghost from 4.39.0 before 6.64.0 contains an information disclosure
  vulnerability in the Admin API that allows staff users to view secret tokens
  of pending staff invites. Staff users with invite viewing permission can
  accept pending invit…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-203
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 4.39.0 < 6.64.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:11.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104416'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-v6q3-xqxm-6f5v'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-4.39.0-before-6.64.0-invite-token-disclosure-via-admin-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.327Z'
---

## Overview

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
