Description
Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of private comments
Action: Upgrade Ghost
AI Analysis

Impact

Ghost versions 5.3.0 through 6.57.9 fail to properly enforce access controls on comments in private mode, allowing unauthenticated visitors to read comments that should be restricted. The flaw is an access control weakness (CWE‑862) that results in confidentiality violations by exposing user commentary; no code execution or other impacts are described.

Affected Systems

The affected product is Ghost, a popular open‑source publishing platform. Versions from 5.3.0 up to, but not including, 6.58.0 are vulnerable. These versions are used by many blogs and small media sites. The vendor associated with the CNAs is TryGhost.

Risk and Exploitability

The CVSS v3.1 score of 6.9 indicates a moderate severity, with likely exploitation via normal HTTP traffic to the public site. The EPSS score is not available, so we cannot quantify current exploit probability. The vulnerability is not listed in the CISA KEV catalog. Attackers can simply access the comment URLs on a public Ghost installation to retrieve private discussions, and because no authentication is required, the attack can be performed from anywhere on the internet.

Generated by OpenCVE AI on October 1, 2026 at 14:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Ghost release (6.58.0 or newer) to eliminate the access control flaw.
  • If upgrading is not immediately possible, limit comment visibility to public or disable comments in private mode to prevent unauthenticated reads.
  • Monitor comment endpoints and log access to detect potential exploitation while a permanent patch is applied.

Generated by OpenCVE AI on October 1, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.
Title Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-862
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T14:41:41.977Z

Reserved: 2026-09-30T10:59:00.638Z

Link: CVE-2026-103274

cve-icon Vulnrichment

Updated: 2026-10-01T14:41:33.234Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:22.897

Modified: 2026-10-01T15:17:26.970

Link: CVE-2026-103274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:15:11Z

Weaknesses