What is CVE-2026-70596?
CVE-2026-70596 is an input validation vulnerability in Ghost CMS versions from 4.9.0 to 6.54.1 that allows any staff user to inject content into the feature_image_caption field to hijack another admin's session, leading to privilege escalation. An update is required to fix this issue.
Azərbaycanca: CVE-2026-70596, Ghost CMS-in 4.9.0-dan 6.54.1-ə qədər versiyalarında aşkar edilmiş input validation zəifliyidir. Bu zəiflik istənilən staff istifadəçisinə feature_image_caption sahəsinə yerləşdirilmiş məzmun vasitəsilə başqa bir adminin sessiyasını ələ keçirməyə və privilege escalation əldə etməyə imkan verir. Problemi aradan qaldırmaq üçün yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Ghost CMS are affected by CVE-2026-70596?
This vulnerability affects Ghost CMS versions from 4.9.0 to 6.54.1.
How does CVE-2026-70596 in Ghost CMS lead to privilege escalation?
The vulnerability allows any staff user to inject content into the feature_image_caption field to hijack another admin's session, resulting in privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.