CVE-2026-103267
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Oct 01, 2026
Vendor
unknown
Description
Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. Attackers can accept leaked invite tokens with attacker-controlled email addresses, or legitimate recipients can register with unintended email providers.