API Key Exposure in Ghost by TryGhost Affects Low-Privilege User Roles
CVE-2026-103281
5.3MEDIUM
What is CVE-2026-103281?
The Ghost platform, developed by TryGhost, presents a vulnerability where authenticated low-privilege staff accounts are able to access sensitive API keys via the Admin API. These API keys are intended to be restricted to higher-privilege users, making this exposure a significant security risk for users employing versions 3.23.0 through to 6.22.2. This issue can allow unauthorized access to sensitive functionalities and data, undermining the integrity of user accounts and the application itself.
Affected Version(s)
Ghost 3.23.0 < 6.23.0
