CVE-2026-103271

Summary

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions by directly querying the content API to retrieve restricted posts without authentication.

Affected Software

VendorProductVersion RangeStatus
TryGhostGhost4.0.0 < 6.63.0affected
TryGhostGhost6.63.0unaffected

Weaknesses

  • CWE-863: Incorrect Authorization

References