Improper access control in Ghost - CVE-2026-70590
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose password hashes of other staff users.
The vulnerability exists due to improper access control in the Ghost Admin API when handling requests for staff user data. A remote privileged user can access password hash data for other staff users to disclose password hashes of other staff users.
User interaction is required, and successful offline password guessing could lead to account takeover.