Content API Vulnerability in Ghost by Ghost Foundation
CVE-2026-103271
8.7HIGH
What is CVE-2026-103271?
A content API vulnerability in Ghost versions prior to 6.63.0 enables unauthenticated users to access restricted posts. This flaw allows malicious actors to bypass authentication measures and retrieve protected content directly through the content API, compromising the intended access controls and exposing sensitive information.
Affected Version(s)
Ghost 4.0.0 < 6.63.0
Ghost 6.63.0
