CVE-2026-103286
ghost: Incorrect Privilege Assignment (CVE-2026-103286)
highEPSS 0.2%
Description
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
bitnamighost
2.21.0Metrics
Show all metrics
Severity
high
72.94
no public PoC known
7.3
8.5
Published
2026-10-09 10:45 UTC
CWE-266
Weakness classes (CWE)
CWE-266Base
Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-01 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-103286","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
- New CVE Received2026-10-01 11:17 UTC· disclosure@vulncheck.com
- Description: Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- CWE: CWE-266