Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-72596

Опубликовано: 11 авг. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.

EPSS

Процентиль: 12%
0.0021
Низкий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.1
debian
8 дней назад

A broken access control vulnerability in Ghost Foundation Ghost 5.x al ...

CVSS3: 8.1
github
8 дней назад

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.

EPSS

Процентиль: 12%
0.0021
Низкий

8.1 High

CVSS3

Дефекты

CWE-284