HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-104416 — Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability...

·Source: NIST NVD

Updated:

Executive Summary

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.

Analysis

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges. CVSS Score: 7.5. Published: 2026-10-02T12:17:11.420.

Indicators of Compromise (1)

CVE (1)
CVE-2026-104416
Source Attribution

Originally published by NIST NVD on Oct 2, 2026. Verified by: NIST.

Related Threats