CVE-2026-103289
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TryGhost | Ghost | 5.9.0 < 6.44.1 | affected |
| TryGhost | Ghost | 6.44.1 | unaffected |
Weaknesses
- CWE-943: Improper Neutralization of Special Elements in Data Query Logic
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-6q6j-f24j-p477
- https://www.vulncheck.com/advisories/ghost-5.9.0-before-6.44.1-authorization-bypass-via-comments
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.