High severity7.5NVD Advisory· Published Oct 1, 2026
CVE-2026-103272
CVE-2026-103272
Description
Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.