Concurrency Issue in Ghost Product Leading to Unauthorized Account Creation
CVE-2026-103282
5.3MEDIUM
What is CVE-2026-103282?
Ghost versions up to 0.5.0, prior to 6.23.0, are affected by a concurrency issue within the invitation acceptance process. This flaw allows attackers to exploit a race condition where multiple accounts can be created using a single invitation token. By submitting simultaneous requests with the same token, an attacker can create duplicate user accounts, posing a significant risk to user management and site integrity.
Affected Version(s)
Ghost 0.5.0 < 6.23.0
