Medium severity4.3NVD Advisory· Published Oct 1, 2026
CVE-2026-103282
CVE-2026-103282
Description
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.