Junglewise Threat Intelligence

CVE-2026-72596: Ghost broken access control in post deletion

CVE-2026-72596 · Severity: high · CVSS 8.1 · Published 2026-08-11

Executive brief

Ghost is a popular open-source publishing platform used for blogs and newsletters. A vulnerability in Ghost 5.x allows users with Author-level permissions to delete any post on the platform, regardless of ownership. This could be exploited by disgruntled staff or compromised Author accounts to destroy critical content and disrupt operations.

Technical details

The vulnerability is a broken access control flaw in the post model's permissible() cascade function. The authorization logic is missing a branch that handles the combined isAuthor and isDestroy condition, causing the access check to fall through and incorrectly permit deletion. An authenticated user with Author role can leverage this to delete posts owned by other users. The flaw requires valid Author credentials but no additional preconditions. An attacker can achieve complete destruction of any published or draft content. Patches should implement the missing authorization condition to properly enforce post ownership checks.

Affected products

  • Ghost Foundation Ghost 5.x

Timeline

  • 2026-08-11: disclosed

References