Junglewise Threat Intelligence

CVE-2026-22595: Ghost Staff Token permission bypass

CVE-2026-22595 · Severity: low · CVSS 3.1 · Published 2026-01-08

Vendors: Ghost.

Executive brief

Ghost is an open-source content management system and publishing platform used to create blogs and newsletters. A vulnerability in Staff Token authentication allowed certain admin endpoints to be accessed by external systems using Staff Tokens that should have been restricted to regular staff sessions, potentially enabling unauthorized data modification or service disruption for authenticated integrations.

Technical details

This is an authorization bypass vulnerability (CWE-863) in Ghost's Staff Token authentication handler. The vulnerability allows certain endpoints intended for Staff Session authentication to be accessed via Staff Tokens by Admin/Owner-role users. The attack requires network access and valid Staff Token credentials (low privilege), with no user interaction needed. An authenticated attacker can modify data integrity and impact service availability through compromised token-based integrations. Patches are available in Ghost v5.130.6 and v6.11.0.

Affected products

  • Ghost Ghost 5.121.0 to 5.130.5, 6.0.0 to 6.10.3

Timeline

  • 2026-01-08: disclosed
  • 2026-01-08: patched: Patches released in v5.130.6 and v6.11.0

References