Authentication Bypass Vulnerability in Ghost by TryGhost
CVE-2026-103273
5.3MEDIUM
What is CVE-2026-103273?
Ghost versions prior to 6.58.0 are susceptible to an authentication bypass issue, allowing lower-privilege staff users to exploit staff tokens. This flaw enables attackers with staff credentials to edit posts beyond their authorized limits, effectively circumventing post editing restrictions meant to protect the integrity of published content.
Affected Version(s)
Ghost 4.3.0 < 6.58.0
Ghost 6.58.0
