Authentication Bypass Vulnerability in Ghost by TryGhost
CVE-2026-103273

5.3MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103273?

Ghost versions prior to 6.58.0 are susceptible to an authentication bypass issue, allowing lower-privilege staff users to exploit staff tokens. This flaw enables attackers with staff credentials to edit posts beyond their authorized limits, effectively circumventing post editing restrictions meant to protect the integrity of published content.

Affected Version(s)

Ghost 4.3.0 < 6.58.0

Ghost 6.58.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.