云虫漏洞库

CVE-2026-72596 - A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform. - 漏洞详情

漏洞编号:CVE-2026-72596

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-72596

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-284

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.

相关链接

相关漏洞

« 返回首页