Improper access control in Ghost - CVE-2026-70590

 

Improper access control in Ghost - CVE-2026-70590

Published: July 30, 2026


Vulnerability identifier: #VU140552
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70590
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose password hashes of other staff users.

The vulnerability exists due to improper access control in the Ghost Admin API when handling requests for staff user data. A remote privileged user can access password hash data for other staff users to disclose password hashes of other staff users.

User interaction is required, and successful offline password guessing could lead to account takeover.


Affected software

Ghost

How to mitigate CVE-2026-70590

Install security update from vendor's website.

Ghost - update to 6.54.1

External References

Related Security Bulletins