CVE-2026-105678Medium· 4.3▾ SunlitGhost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104412Medium· 4.3Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so
CVE-2026-105679High· 7.3Ghost is a Node.js content management system
CVE-2026-105677High· 7.2Ghost is a Node.js content management system
CVE-2026-105650High· 8.1Ghost is a Node.js content management system
CVE-2026-105651High· 7.3Ghost is a Node.js content management system
CVE-2026-105652Low· 3.1Ghost is a Node.js content management system