Input Validation Flaw in Ghost Affects User Account Security
CVE-2026-103278

8.5HIGH

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103278?

Ghost versions prior to 6.34.0 are prone to an input validation vulnerability located in the admin iframe. This flaw allows attackers with content publishing rights to create malicious pages. When interacted with by active staff users, these pages can facilitate account takeover through inadequate validation mechanisms, compromising user accounts and potentially affecting the integrity of the application. Organizations utilizing affected versions should prioritize updating to ensure robust security.

Affected Version(s)

Ghost 5.8.0 < 6.34.0

Ghost 6.34.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.