API Key Exposure in Ghost by TryGhost Affects Low-Privilege User Roles
CVE-2026-103281

5.3MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103281?

The Ghost platform, developed by TryGhost, presents a vulnerability where authenticated low-privilege staff accounts are able to access sensitive API keys via the Admin API. These API keys are intended to be restricted to higher-privilege users, making this exposure a significant security risk for users employing versions 3.23.0 through to 6.22.2. This issue can allow unauthorized access to sensitive functionalities and data, undermining the integrity of user accounts and the application itself.

Affected Version(s)

Ghost 3.23.0 < 6.23.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.