Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103273

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 01, 2026
Vendor unknown

Description

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.

References