OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104418

HIGH · CVSS 7.2 EPSS 0.65% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Authenticated administrators using Ghost versions prior to 6.64.0 are vulnerable to a remote code execution flaw that allows the execution of arbitrary code through malicious theme translation files. This vulnerability poses a significant risk as it enables attackers with admin access to compromise the Ghost server by uploading crafted themes. Organizations utilizing affected versions should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104418
Severity
HIGH
CVSS
7.2
EPSS
0.65%

Original NVD Description

Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers with administrator access can upload a crafted theme containing malicious translation files to execute arbitrary code on the Ghost server.