PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105680 TryGhost CVE debrief

CVE-2026-105680 debrief: A vulnerability in Ghost allows Author role users to delete posts and pages they did not author. This issue exists from version 5.81.0 up to 6.60.0. Users should update to version 6.60.0. System administrators and Ghost users with the Author role should assess exposure and prioritize updating vulnerable instances. This vulnerability allows unauthorized deletion of posts and pages, potentially leading to data loss and integrity issues. Affected instances should be identified and updated promptly.

Vendor
TryGhost
Product
ghost
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

System administrators and Ghost users with the Author role should assess exposure and prioritize updating vulnerable instances. This includes reviewing current Ghost deployments, identifying instances with users in the Author role, and ensuring that these instances are updated to version 6.60.0 or later. Additionally, defenders should verify post deletion functionality after updates and review logs for suspicious activity.

Why it matters

CVE-2026-105680 allows Author role users in Ghost to delete posts and pages they did not author. System administrators and Ghost users with the Author role should assess exposure and prioritize updating vulnerable instances.

  • Author role users can delete unauthorized posts and pages
  • Requires verification of affected versions and instance updates
  • Prioritize updating vulnerable Ghost instances
  • Defenders should verify post deletion functionality after updates

Technical summary

A vulnerability in Ghost allows users with the Author role to delete posts and pages they did not author. This issue exists from version 5.81.0 up to 6.60.0. The fix is included in version 6.60.0. This vulnerability is a result of insufficient authorization checks, allowing Author role users to perform actions beyond their intended permissions. Technical details include the need to update affected instances to prevent unauthorized post deletion and ensure data integrity. Defenders should focus on updating vulnerable instances and verifying the effectiveness of the update.

Defensive priority

Medium

Recommended defensive actions

  • Update Ghost to version 6.60.0 or later
  • Assess exposure for Ghost instances with users in the Author role
  • Verify instance updates and test post deletion functionality
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability allows users with the Author role to delete posts and pages they did not author. This issue is present in Ghost from version 5.81.0 up to 6.60.0. The fix is included in version 6.60.0. Evidence of this vulnerability includes instances where Author role users have deleted unauthorized posts or pages. Defenders should verify post deletion functionality after updates and review logs for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105680 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105680

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105680 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105680

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Ghost: Authorization Issue Allowed Author Role to Delete any Post

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-x3mg-q38v-m562.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-x3mg-q38v-m562

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/issues/30283

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/commit/cf2f718a67faa342c27989b701554ddd63862165

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/releases/tag/v6.60.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.