Authorization bypass through user-controlled key in Ghost - CVE-2026-59817
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to obtain paid gift memberships for a minimal payment.
The vulnerability exists due to authorization bypass through a user-controlled key in Ghost's public donation checkout flow when processing donation checkout requests. A remote attacker can submit a crafted checkout request to obtain paid gift memberships for a minimal payment.
No customer or member data is exposed, and the issue cannot be used to steal money from a site or its members.