Loading market data...
← Back to CVE feed

CVE-2026-103267

MEDIUM CVSS 4.3 View on NVD ↗

Description

Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Published: Oct 01, 2026 11:17 UTC Modified: Oct 01, 2026 17:17 UTC