Password Leakage Vulnerability in Ghost CMS by TryGhost
CVE-2026-70590

4.8MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70590?

The Ghost content management system, prior to version 6.54.1, was found to have a vulnerability that allowed staff-level users to inadvertently access the hashed passwords of other staff members via the Ghost Admin API. This flaw posed a risk of offline password-guessing attacks where attackers could potentially exploit the leaked hashes for account access. Although Device Verification was implemented to guard against unauthorized logins with recovered passwords, the uniqueness of case characters in hash representation could further complicate guessing attempts. The issue has been addressed in the latest version, 6.54.1.

Affected Version(s)

Ghost < 6.54.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.