Description
Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

Ghost, an open‑source publishing platform, contains an input validation flaw in its comment like feature. An authenticated member can delete comment likes or dislikes belonging to other users, bypassing the intended authorization controls. This unauthorized modification allows the attacker to alter comment engagement data, potentially skewing analytics or user experience.

Affected Systems

The affected product is Ghost published by TryGhost. Versions from 5.9.0 up through 6.44.0 are vulnerable; all releases 6.44.1 and newer include the fix.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating a high severity. Evidence of exploitation is not documented (EPSS is unavailable) and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a locally authenticated user. An attacker needs valid credentials with commenting permissions but does not require elevated privileges; the data modification does not grant control over the system as a whole, yet permits changing observable engagement metrics.

Generated by OpenCVE AI on October 1, 2026 at 14:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Ghost installation to version 6.44.1 or later, which includes the fix for the comment like authorization flaw.
  • Restrict comment like deletion capabilities for non‑administrator roles where feasible to mitigate potential abuse.
  • Audit existing comment engagement data for signs of unauthorized deletions and restore any affected records from backups if necessary.

Generated by OpenCVE AI on October 1, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.
Title Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-639
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:28:31.759Z

Reserved: 2026-09-30T10:59:26.443Z

Link: CVE-2026-103288

cve-icon Vulnrichment

Updated: 2026-10-01T13:28:15.953Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:25.200

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key