Information Disclosure in Ghost Versions by Ghost Foundation
CVE-2026-103284

5.3MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103284?

Ghost versions prior to 6.57.1 are vulnerable to an information disclosure issue in the Admin Feedback endpoint. This vulnerability may allow unauthorized staff users to gain access to confidential member data. Attackers with staff privileges can exploit the feedback endpoint, allowing retrieval of sensitive information without undergoing proper authorization checks. This raises significant concerns over data security and the integrity of user information.

Affected Version(s)

Ghost 5.125.1 < 6.57.1

Ghost 6.57.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

default-cybe
doanmanhducz
.