Incorrect authorization in Ghost - CVE-2026-103266

 

Incorrect authorization in Ghost - CVE-2026-103266

Published: September 7, 2026 / Updated: October 1, 2026


Vulnerability identifier: #VU147286
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-103266
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify existing member accounts and inject content into newsletters.

The vulnerability exists due to incorrect authorization in Stripe Checkout when processing checkout requests. A remote attacker can attach a paid subscription to an existing member and modify their name to modify existing member accounts and inject content into newsletters.

User interaction is required for malicious newsletter content to be rendered.


Affected software

Ghost

How to mitigate CVE-2026-103266

Install security update from vendor's website.

Ghost - update to 6.62.0

External References

Related Security Bulletins