CVE-2026-103275

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
4.3
MEDIUM

Description

Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.password, because of an incomplete fix for CVE-2026-70590. Staff-level attackers can infer other staff users' password hashes from which filters match and perform offline password-guessing attacks against them.

Published
October 1, 2026 11:17 AM
Last Modified
October 1, 2026 11:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-203

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.