Vulnerabilidad · Publicado 01/10/2026
Ghost, plataforma de contenido de código abierto ampliamente usada en LATAM, contiene una vulnerabilidad de escalada de privilegios (CVSS 7.3) en su sistema de notificaciones. Usuarios con acceso de personal de bajo nivel pueden elevar sus permisos a roles administrativos sin autorización válida. El riesgo es alto para empresas que ejecutan Ghost auto-alojado o en infraestructura propia en México y Latinoamérica.
Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff roles. Attackers with low-privilege staff access can exploit the notifications system to gain elevated privileges without proper authorization checks.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CWE-266
Publicado en NIST NVD.