CVE-2026-103284
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TryGhost | Ghost | 5.125.1 < 6.57.1 | affected |
| TryGhost | Ghost | 6.57.1 | unaffected |
Weaknesses
- CWE-863: Incorrect Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-vm82-r49m-224q
- https://www.vulncheck.com/advisories/ghost-5.125.1-before-6.57.1-information-disclosure-via-feedback
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.