High severity8.1NVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2026-72596
CVE-2026-72596
Description
A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 5.x
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.