VYPR
advisoryPublished Oct 1, 2026· Updated Oct 2, 2026· 1 source

Ghost CMS: 19 Vulnerabilities Disclosed in Single-Day Batch, Affecting Authentication and Data Security

Key findings • 19 vulnerabilities disclosed for Ghost CMS on October 1, 2026, spanning authentication, authorization, and information disclosure. • High severity flaws include session hijacki…

Key findings

  • 19 vulnerabilities disclosed for Ghost CMS on October 1, 2026, spanning authentication, authorization, and information disclosure.
  • High severity flaws include session hijacking, privilege escalation, and untrusted script execution.
  • Multiple vulnerabilities allow unauthorized access to sensitive data, including user information and private comments.
  • Affected versions vary, with patches available in releases up to 6.63.0; immediate updates are recommended.
  • Issues range from path traversal and SSRF to script injection and content API bypasses.

On October 1, 2026, a significant batch of 19 vulnerabilities was disclosed for the Ghost content management system. These vulnerabilities, spanning a range of severities from Low to High, were all disclosed on the same day, indicating a coordinated disclosure event. The issues affect various aspects of the Ghost platform, including authentication, authorization, information disclosure, and script execution, posing a considerable risk to users if left unpatched.

Several vulnerabilities center on authentication and authorization bypass. CVE-2026-103283, a High severity flaw, allows authenticated staff users to log in as any other staff user by only knowing their password, bypassing two-factor authentication due to improper session handling. Similarly, CVE-2026-103268, also High severity, permits suspended staff users to reactivate their accounts via self-service password reset, effectively bypassing suspension. CVE-2026-103273, a Medium severity issue, enables lower-privilege staff users to bypass post editing restrictions using staff tokens. Another Medium severity vulnerability, CVE-2026-103267, affects staff invite acceptance, allowing users to specify any email address, potentially leading to account takeover or unintended registrations.

Information disclosure is another prominent theme within this batch. CVE-2026-103280 (Medium) exposes the site owner's email address through the setup endpoint to unauthenticated requests. CVE-2026-103284 (Medium) allows unauthorized staff users to access member data via the Admin Feedback endpoint. CVE-2026-103272 (High) enables unauthenticated attackers to enumerate staff members and extract sensitive information through the content API. Furthermore, CVE-2026-103275 (Medium) involves an information disclosure in the Admin API's bulk post and page edit/delete endpoints, allowing staff-level attackers to infer other staff users' password hashes. CVE-2026-103274 (Medium) allows unauthenticated visitors to read comments in private mode, bypassing privacy settings.

Script execution and data injection vulnerabilities also feature in this disclosure. CVE-2026-103292 (High) allows authenticated users with limited privileges to inject unescaped content into the JSON-LD HTML tag emitted by the {{ghost_head}} helper, potentially leading to script execution on published pages. CVE-2026-103277 (High) is an untrusted script execution vulnerability in the oEmbed preview feature, failing to sandbox externally hosted scripts and allowing attackers to execute scripts in the context of a staff user's admin session. CVE-2026-103266 (High) abuses the Stripe Checkout flow to attach paid subscriptions to existing members, modify member names, and inject content into newsletters.

Other notable vulnerabilities include CVE-2026-103291 (Medium), a server-side request forgery (SSRF) in image dimension refetching that allows authenticated staff users to trigger outbound HTTP requests to arbitrary URLs. CVE-2026-103290 (Low) is a path traversal vulnerability in the ImageSize service, allowing authenticated staff users to access local files. CVE-2026-103289 (Medium) involves an input validation issue in the comments feature, allowing authenticated members to access unauthorized comments. CVE-2026-103288 (Medium) permits authenticated members to delete comment likes or dislikes belonging to other users. Lastly, CVE-2026-103286 (High) is a privilege escalation vulnerability in the notifications system, allowing low-privilege staff users to gain elevated privileges. CVE-2026-103271 (High) allows unauthenticated visitors to access gated post content by bypassing restrictions via the content API. CVE-2026-103282 (Medium) is a concurrency issue in staff invitation acceptance, allowing multiple accounts to be created from a single invite token.

The affected versions vary across these CVEs, with patches generally available in newer releases. For instance, CVE-2026-103292 is fixed in versions prior to 6.50.0, CVE-2026-103291 in versions prior to 6.51.0, and CVE-2026-103290 in versions prior to 6.27.0. Many other vulnerabilities are addressed in versions 6.44.1, 6.57.1, 6.58.0, 6.62.0, or 6.63.0. Users are strongly advised to update their Ghost installations to the latest available versions to mitigate these security risks.

This extensive batch of vulnerabilities underscores the importance of regular security audits and timely patching for the Ghost platform. The wide range of issues, from authentication bypass to script injection and information disclosure, highlights potential attack vectors that could compromise user data and system integrity. Staying current with Ghost updates is crucial for maintaining a secure publishing environment.

Synthesized by Vypr AI