HIGH
Ghost Foundation
CVE published 2026-08-11
CVE-2026-72596
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:42.543Z and has not been modified since then. CVE-2026-72596 is a broken access control vulnerability in Ghost Foundation Ghost 5.x that allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the c [truncated]