PatchSiren cyber security CVE debrief
CVE-2026-105680 TryGhost CVE debrief
CVE-2026-105680 debrief: A vulnerability in Ghost allows Author role users to delete posts and pages they did not author. This issue exists from version 5.81.0 up to 6.60.0. Users should update to version 6.60.0. System administrators and Ghost users with the Author role should assess exposure and prioritize updating vulnerable instances. This vulnerability allows unauthorized deletion of posts and pages, potentially leading to data loss and integrity issues. Affected instances should be identified and updated promptly.
- Vendor
- TryGhost
- Product
- ghost
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
System administrators and Ghost users with the Author role should assess exposure and prioritize updating vulnerable instances. This includes reviewing current Ghost deployments, identifying instances with users in the Author role, and ensuring that these instances are updated to version 6.60.0 or later. Additionally, defenders should verify post deletion functionality after updates and review logs for suspicious activity.
Why it matters
CVE-2026-105680 allows Author role users in Ghost to delete posts and pages they did not author. System administrators and Ghost users with the Author role should assess exposure and prioritize updating vulnerable instances.
- Author role users can delete unauthorized posts and pages
- Requires verification of affected versions and instance updates
- Prioritize updating vulnerable Ghost instances
- Defenders should verify post deletion functionality after updates
Technical summary
A vulnerability in Ghost allows users with the Author role to delete posts and pages they did not author. This issue exists from version 5.81.0 up to 6.60.0. The fix is included in version 6.60.0. This vulnerability is a result of insufficient authorization checks, allowing Author role users to perform actions beyond their intended permissions. Technical details include the need to update affected instances to prevent unauthorized post deletion and ensure data integrity. Defenders should focus on updating vulnerable instances and verifying the effectiveness of the update.
Defensive priority
Medium
Recommended defensive actions
- Update Ghost to version 6.60.0 or later
- Assess exposure for Ghost instances with users in the Author role
- Verify instance updates and test post deletion functionality
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability allows users with the Author role to delete posts and pages they did not author. This issue is present in Ghost from version 5.81.0 up to 6.60.0. The fix is included in version 6.60.0. Evidence of this vulnerability includes instances where Author role users have deleted unauthorized posts or pages. Defenders should verify post deletion functionality after updates and review logs for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105680 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105680
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105680 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105680
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Ghost: Authorization Issue Allowed Author Role to Delete any Post
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-x3mg-q38v-m562.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-x3mg-q38v-m562
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/issues/30283
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/commit/cf2f718a67faa342c27989b701554ddd63862165
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/releases/tag/v6.60.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.