CVE-2026-105680 Overview
CVE-2026-105680 is a missing authorization vulnerability [CWE-862] in Ghost, a Node.js content management system. Staff users assigned the Author role could delete posts and pages that they did not author. The flaw affects versions 5.81.0 through 6.59.x and is resolved in version 6.60.0.
The issue stems from an incomplete permission check in the post authorization logic. Authors are permitted to destroy content records without being validated as the primary author of the resource. An authenticated staff member with low privileges can abuse this gap to remove arbitrary posts and pages across the site.
Critical Impact
Any authenticated user with the Author role can delete posts and pages belonging to other authors, resulting in content loss and availability impact across the Ghost publication.
Affected Products
- Ghost (Node.js CMS) versions 5.81.0 through 6.59.x
- Self-hosted Ghost installations within the affected version range
- Ghost(Pro) deployments prior to the 6.60.0 release
Discovery Timeline
- 2026-10-05 - CVE-2026-105680 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-105680
Vulnerability Analysis
The vulnerability lives in Ghost's post permission logic within ghost/core/core/server/models/relations/authors.js. The function evaluates whether a user may add, edit, or destroy a given post based on their role. The destroy branch originally handled only the Contributor role, omitting equivalent primary-author verification for the Author role.
As a result, when an Author issued a destroy action against a post, the permission check fell through to a more permissive branch and returned a successful authorization. The server then processed the deletion against the database without validating ownership. Authors could remove any post or page in the publication, including content authored by Editors, Administrators, or the Owner.
The impact is limited to integrity of the publication workflow and availability of content. The flaw does not expose confidential data, but it enables destructive actions beyond the intended role boundary.
Root Cause
The root cause is a missing authorization check [CWE-862] in the role-based access control (RBAC) matrix. The destroy conditional explicitly tested for Contributors but did not include Authors in the primary-author verification path. The patch extends both the isAdd and isDestroy branches to cover (isContributor || isAuthor) and requires a valid postModel before granting destroy permission.
Attack Vector
Exploitation requires an authenticated session with the Author role. The attacker issues a standard delete request through the Ghost Admin API against any post or page identifier. No user interaction from the victim is needed, and no additional privileges are required beyond the Author role.
// Patch from ghost/core/core/server/models/relations/authors.js
// Source: https://github.com/TryGhost/Ghost/commit/cf2f718a67faa342c27989b701554ddd63862165
if (isContributor && isEdit) {
hasUserPermission = !isChangingAuthors() && isCoAuthor();
- } else if (isContributor && isAdd) {
+ } else if ((isContributor || isAuthor) && isAdd) {
hasUserPermission = isOwner();
- } else if (isContributor && isDestroy) {
- hasUserPermission = isPrimaryAuthor();
+ } else if ((isContributor || isAuthor) && isDestroy) {
+ hasUserPermission = Boolean(postModel) && isPrimaryAuthor();
} else if (isAuthor && isEdit) {
hasUserPermission = isCoAuthor() && !isChangingAuthors();
- } else if (isAuthor && isAdd) {
- hasUserPermission = isOwner();
} else if (postModel) {
hasUserPermission = hasUserPermission || isPrimaryAuthor();
}
The fix enforces that an Author must be the primary author of a referenced postModel to delete it. See the GitHub Security Advisory GHSA-x3mg-q38v-m562 for additional context.
Detection Methods for CVE-2026-105680
Indicators of Compromise
- Deletion events in the Ghost activity log where the acting user has the Author role and the target post or page was authored by a different user.
- Unexpected DELETE /ghost/api/admin/posts/{id}/ or DELETE /ghost/api/admin/pages/{id}/ requests from low-privilege staff sessions.
- Audit log entries showing missing or recently removed posts without a corresponding Editor or Admin action.
Detection Strategies
- Review Ghost audit logs and database actions records for destroy events correlated with Author-role sessions.
- Compare current post inventories against recent backups to identify posts that disappeared without an authorized workflow.
- Monitor web server access logs for DELETE requests to the Admin API originating from accounts not assigned Editor or Administrator roles.
Monitoring Recommendations
- Enable verbose logging on the Ghost Admin API and forward events to a centralized SIEM or data lake for correlation.
- Alert on any post or page deletion performed by a staff account with the Author role.
- Track role assignments and flag privilege changes applied to accounts prior to large-volume deletion activity.
How to Mitigate CVE-2026-105680
Immediate Actions Required
- Upgrade Ghost to version 6.60.0 or later on all production and staging deployments.
- Audit staff accounts and remove or demote Author-role users that are not strictly required.
- Restore any posts or pages identified as improperly deleted from the most recent clean backup.
Patch Information
The fix is included in Ghost 6.60.0. The patch commit cf2f718a67faa342c27989b701554ddd63862165 updates ghost/core/core/server/models/relations/authors.js to require primary-author verification before an Author can destroy a post. Refer to the GitHub Release Notes v6.60.0 and the GitHub Issue Discussion for release details.
Workarounds
- Temporarily reassign Author-role users to the Contributor role until the upgrade to 6.60.0 is completed.
- Restrict access to the Ghost Admin API using a reverse proxy or WAF rule that blocks DELETE requests from non-administrative accounts.
- Increase backup frequency for the Ghost content database to minimize potential data loss while the patch is being deployed.
# Upgrade a self-hosted Ghost installation to the patched release
cd /var/www/ghost
ghost update --version 6.60.0
ghost ls
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.