CVE-2026-103286

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.3
HIGH

Description

Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.

Published
October 1, 2026 11:17 AM
Last Modified
October 1, 2026 11:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-266

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.