Vulnerability Description
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/GhostManager/Ghostwriter
- https://github.com/GhostManager/Ghostwriter/blob/v7.1.1/ghostwriter/reporting/vi
- https://github.com/GhostManager/Ghostwriter/commit/5b2a4a297e44c823c16f65b1ba101
- https://github.com/geo-chen/oss/blob/main/Ghostwriter.md
- https://www.vulncheck.com/advisories/ghostwriter-before-cross-client-report-temp
FAQ
What is CVE-2026-78203?
CVE-2026-78203 is a vulnerability with a CVSS score of 7.1 (HIGH). Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attack...
How severe is CVE-2026-78203?
CVE-2026-78203 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-78203?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.