ID:12730 - Exploit for SQL injection in Ghost - CVE-2026-26980
Published: May 22, 2026
Vulnerability identifier: #VU128207
Vulnerability risk: High
CVE-ID: CVE-2026-26980
CWE-ID: CWE-89
Exploitation vector: Remote access
Vulnerable software:
Ghost
Ghost
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to sql injection in the Content API when processing crafted filter query parameters. A remote attacker can send a specially crafted request to disclose sensitive information.
Remediation
Install security update from vendor's website.