Executive brief
Ghostwriter, a project management and reporting platform used by security teams, fails to properly validate template ownership when swapping report templates. An attacker can enumerate and attach templates belonging to other clients and use them to generate reports that expose sensitive content like client letterheads, boilerplate text, and methodology details. This breaks data isolation between clients and risks disclosing confidential business information.
Technical details
The vulnerability is an authorization bypass in the report template swap endpoint due to insufficient ownership validation. An attacker can leverage sequential template primary keys to enumerate templates across the system and attach client-scoped templates from other organizations to their own reports. The endpoint fails to verify that a template belongs to the attacker's client before allowing the swap operation. Once a foreign template is attached, the attacker can generate reports that render and disclose the template contents, including letterhead, boilerplate text, and methodology information. Versions prior to 7.1.2 are affected; a patch is available.
Affected products
- SpecterOps Ghostwriter before 7.1.2
Timeline
- 2026-08-24: disclosed
- 2026: patched: Version 7.1.2 fixes the vulnerability