Description
Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visited by active staff users, enable account takeover through improper input validation.
Published: 2026-10-01
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Staff Account Takeover
Action: Patch
AI Analysis

Impact

Ghost versions 5.8.0 through 6.33.99 contain an input validation vulnerability in the admin iframe that enables attackers with content publishing privileges to create malicious pages. When a staff user visits such a crafted page, the iframe can be manipulated to take over the staff account, compromising the user's credentials and any associated privileges. The flaw is rooted in CWE‑23, a Path Traversal weakness in input handling that allows attackers to hijack authenticated sessions. This leads to full account compromise, potentially exposing sensitive content, administrative controls, and other staff users.

Affected Systems

The affected products are TryGhost Ghost running any version earlier than 6.34.0, specifically from 5.8.0 up to 6.33.99. Users deploying Ghost on these releases should verify their version against the vendor’s release notes and ensure it is not included in the vulnerable range.

Risk and Exploitability

The vulnerability has a CVSS score of 8.5, indicating high severity. EPSS data is not available, so the attack probability cannot be quantified, and it has not been listed in the CISA KEV catalog. Attackers must have the ability to publish content within Ghost or otherwise send malicious links to staff users, implying the threat is limited to environments where the attacker can control published content or phish staff members. If such conditions exist, the risk is significant and the vulnerability is exploitable without requiring user interaction beyond visiting a crafted page.

Generated by OpenCVE AI on October 1, 2026 at 14:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.34.0 or later to apply the vendor fix
  • If an immediate upgrade is not possible, remove or disable the admin iframe functionality for all users until the patch is applied
  • Revoke or restrict content publishing privileges for untrusted users until the vulnerability is resolved

Generated by OpenCVE AI on October 1, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visited by active staff users, enable account takeover through improper input validation.
Title Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-23
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T14:36:29.984Z

Reserved: 2026-09-30T10:59:00.638Z

Link: CVE-2026-103278

cve-icon Vulnrichment

Updated: 2026-10-01T14:36:26.413Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:23.567

Modified: 2026-10-01T15:17:27.100

Link: CVE-2026-103278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:09Z

Weaknesses
  • CWE-23

    Relative Path Traversal