CVE-2026-103274

Summary

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.

Affected Software

VendorProductVersion RangeStatus
TryGhostGhost5.3.0 < 6.58.0affected
TryGhostGhost6.58.0unaffected

Weaknesses

  • CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References