CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105678
MEDIUMCVSS 4.3NVD feed
Published 5 October 2026 · tracked since 6 October 2026
Description
Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-95264
- CVE-2026-97257 HIGH 8.8
- CVE-2026-93617 HIGH 7.2
- CVE-2026-105766 LOW 3.1
- CVE-2026-105767 LOW 3.3
- CVE-2026-105683 LOW 3.8
- CVE-2026-105681 MEDIUM 6.5
- CVE-2026-105682 LOW 2.7
- CVE-2026-105679 HIGH 7.3
- CVE-2026-105680 MEDIUM 6.5