Loading market data...
← Back to CVE feed

CVE-2026-103273

MEDIUM CVSS 4.3 View on NVD ↗

Description

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Published: Oct 01, 2026 11:17 UTC Modified: Oct 01, 2026 15:06 UTC