← Retour
CVE-2026-78203
high
CVSS 7.1
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap...
Résumé
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-78203** a été découverte dans ghostwriter.
Des informations confidentielles peuvent être exposées. Score CVSS : 7.1/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « ghostwriter CVE-2026-78203 » sur le site de l'éditeur.
CVE-2026-78203 (ghostwriter) — CWE-639 / CVSS v3 7.1
Vecteur d'attaque : distant (réseau) / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Ghostwriterにおけるレポートテンプレートの所有権検証不備による情報漏洩の脆弱性。
📍 Périmètre concerné
Ghostwriterのバージョン7.1.2より前のバージョン。
🔥 Gravité
テンプレートの非許可な付加と内容漏洩が可能であり、機密情報が流出する恐れがあるため重要。
🔧 Comment corriger
バージョン7.1.2 以上へのアップグレードを推奨。
🛡️ Contournement
情報なし。
🔍 Détection
テンプレートキーを確認し、非許可のテンプレートが使用されていないかを確認する。