ID:12730 - Exploit for SQL injection in Ghost - CVE-2026-26980

 
Main Vulnerability Database Exploits ID:12730 - Exploit for SQL injection in Ghost - CVE-2026-26980

ID:12730 - Exploit for SQL injection in Ghost - CVE-2026-26980

Published: May 22, 2026


Vulnerability identifier: #VU128207
Vulnerability risk: High
CVE-ID: CVE-2026-26980
CWE-ID: CWE-89
Exploitation vector: Remote access
Vulnerable software:
Ghost

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to sql injection in the Content API when processing crafted filter query parameters. A remote attacker can send a specially crafted request to disclose sensitive information.


Remediation

Install security update from vendor's website.