Description
Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.
Published: 2026-10-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthenticated staff enumeration and data leakage
Action: Apply Patch
AI Analysis

Impact

Ghost content API versions from 2.10.0 through just before 6.63.0 allow an attacker who does not need to authenticate to discover which users are registered as staff. By sending crafted requests to the API, an attacker can observe differences in metadata responses and use those discrepancies to enumerate staff members and extract sensitive information. This can expose personal data, contact details, or other confidential information belonging to staff, thereby compromising the confidentiality of the site’s user base. The weakness is a common identifier for information disclosure vulnerabilities, CWE-203.

Affected Systems

Vendors affected are TryGhost, product Ghost. Anyone running Ghost version 2.10.0, 3.x, 4.x, 5.x or 6.x prior to 6.63.0 is potentially vulnerable. The vulnerable range includes every release within that bracket; no specific minor patches are listed that address the issue.

Risk and Exploitability

The CVSS score of 8.7 rates this as high severity, reflecting significant impact if exploited. The EPSS score is not available, but the vulnerability is listed as not currently part of the CISA KEV catalog, indicating no confirmed public exploitation. The likely attack vector is a remote unauthenticated API call over the network, as the flaw requires no credentials. Because the attacker can trigger enumeration without any need to login, the logistical barrier to exploit is minimal. All evidence for exploitation derives from the official vulnerability advisory and the impact description; no additional details are present.

Generated by OpenCVE AI on October 1, 2026 at 13:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.63.0 or later to eliminate the enumeration flaw
  • If an upgrade is not immediately possible, configure firewall or reverse‑proxy rules to restrict access to the content API to only authenticated users or internal hosts
  • After configuration changes, validate that API responses no longer reveal staff metadata by performing test queries from an unauthenticated source

Generated by OpenCVE AI on October 1, 2026 at 13:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.
Title Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-203
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T16:31:47.708Z

Reserved: 2026-09-30T10:58:33.573Z

Link: CVE-2026-103272

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:22.563

Modified: 2026-10-01T17:17:18.317

Link: CVE-2026-103272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:30:10Z

Weaknesses