CVE-2026-103269

Summary

Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).

Affected Software

VendorProductVersion RangeStatus
TryGhostGhost5.3.0 < 6.62.0affected
TryGhostGhost6.62.0unaffected

Weaknesses

  • CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References