Incorrect authorization in Ghost - CVE-2026-103266
Published: September 7, 2026 / Updated: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify existing member accounts and inject content into newsletters.
The vulnerability exists due to incorrect authorization in Stripe Checkout when processing checkout requests. A remote attacker can attach a paid subscription to an existing member and modify their name to modify existing member accounts and inject content into newsletters.
User interaction is required for malicious newsletter content to be rendered.