Staff Enumeration Vulnerability in Ghost Content API by Ghost
CVE-2026-103272

8.7HIGH

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103272?

The Ghost Content API, specifically in versions ranging from 2.10.0 to 6.63.0, contains a vulnerability that permits unauthenticated attackers to enumerate staff members. By exploiting discrepancies in API metadata responses, attackers can extract sensitive information about users without needing authentication. This vulnerability poses a significant risk as it enables potential data leaks, highlighting the importance of securing access to user-related data within the API.

Affected Version(s)

Ghost 2.10.0 < 6.63.0

Ghost 6.63.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.