OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104416

HIGH · CVSS 7.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in Ghost versions prior to 6.64.0 allows staff users with invite viewing permissions to access secret tokens for pending staff invites, potentially enabling them to accept invites for higher-privileged roles and escalate their privileges. Organizations using affected versions of Ghost should prioritize patching to mitigate the risk of unauthorized privilege escalation and protect sensitive administrative functions. This issue is particularly critical for environments where multiple staff users have varying levels of access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104416
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges.