CVE-2026-103289

Summary

Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.

Affected Software

VendorProductVersion RangeStatus
TryGhostGhost5.9.0 < 6.44.1affected
TryGhostGhost6.44.1unaffected

Weaknesses

  • CWE-943: Improper Neutralization of Special Elements in Data Query Logic

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References