Observable discrepancy in Ghost - #VU144566
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to disclose password hashes of other staff users.
The vulnerability exists due to observable discrepancy in the Ghost Admin API when handling staff-level administrative requests. A remote user can access crafted API interactions to disclose password hashes of other staff users.
An offline password-guessing attack against the disclosed hashes could lead to account takeover if successful, although device verification may prevent login with a recovered password.