Password Leakage Vulnerability in Ghost CMS by TryGhost
CVE-2026-70590
4.8MEDIUM
What is CVE-2026-70590?
The Ghost content management system, prior to version 6.54.1, was found to have a vulnerability that allowed staff-level users to inadvertently access the hashed passwords of other staff members via the Ghost Admin API. This flaw posed a risk of offline password-guessing attacks where attackers could potentially exploit the leaked hashes for account access. Although Device Verification was implemented to guard against unauthorized logins with recovered passwords, the uniqueness of case characters in hash representation could further complicate guessing attempts. The issue has been addressed in the latest version, 6.54.1.
Affected Version(s)
Ghost < 6.54.1
