{"apiVersion":"1.0","identifier":"CVE-2026-78204","description":"Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test_func returns only request.user.is_active unless a view overrides it, and neither the endpoint that lints a report template nor the endpoint that returns stored lint results provides an override, so each resolves a ReportTemplate from a caller-supplied primary key with no ownership or client-scope check. Any authenticated account can therefore lint an arbitrary template, which overwrites that template-s stored lint result, and can read the returned findings, which enumerate the template-s variable names and template-engine errors and so disclose its structure. This is distinct from the template swap path: that endpoint authorizes the report but omits the per-template check, whereas these endpoints omit authorization entirely and remain unfixed.","publishedAt":"2026-08-24T01:16:57","lastModifiedAt":"2026-08-26T17:10:53","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78204","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","epssProbability":0.00223,"riskScore":0.55,"affectedProduct":"Ghostwriter","affectedVersions":"<=7.2.6","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-78204","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-78204","en":"https://www.redsauce.net/en/cves/CVE-2026-78204","fr":"https://www.redsauce.net/fr/cves/CVE-2026-78204","pt":"https://www.redsauce.net/pt/cves/CVE-2026-78204","de":"https://www.redsauce.net/de/cves/CVE-2026-78204","sk":"https://www.redsauce.net/sk/cves/CVE-2026-78204","el":"https://www.redsauce.net/el/cves/CVE-2026-78204"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-78204"}}