Description
Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password recovery.
Published: 2026-10-02
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure – relative ordering of password hashes
Action: Patch
AI Analysis

Impact

Ghost from version 0.7.2 before 6.64.0 has an information disclosure flaw in its Admin API that allows authenticated staff users to infer the relative ordering of password hashes of other staff members. While this does not reveal actual hash values, it gives attackers a measurable advantage when attempting brute‑force or dictionary attacks. The weakness is classified as CWE‑203.

Affected Systems

TryGhost Ghost installations running any version from 0.7.2 up through 6.63.x, inclusive, are affected. The issue exists in the public GitHub releases and is referenced in GitHub Advisory GHSA‑53vv‑xm9f‑mm82. Staff or other authenticated users with Admin API permissions can exploit it.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation momentum. Nevertheless, because the relative ordering may reduce the effort required for a password‑cracking campaign, organizations should treat it as a low‑risk, but actionable, disclosure that can be mitigated by upgrading or restricting Admin API access.

Generated by OpenCVE AI on October 2, 2026 at 12:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.64.0 or later to remove the vulnerability
  • Ensure the Admin API is protected by role‑based access control, allowing only essential staff to invoke it
  • Disable or restrict Admin API usage for non‑essential accounts and monitor logs for anomalous requests

Generated by OpenCVE AI on October 2, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password recovery.
Title Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-203
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T15:52:21.642Z

Reserved: 2026-10-02T00:44:44.529Z

Link: CVE-2026-104415

cve-icon Vulnrichment

Updated: 2026-10-02T15:52:17.649Z

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:11.270

Modified: 2026-10-02T16:16:45.170

Link: CVE-2026-104415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses