Medium severity4.3NVD Advisory· Published Oct 1, 2026
CVE-2026-103273
CVE-2026-103273
Description
Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.