Missing Authorization in Ghost - CVE-2026-103269
Published: September 7, 2026 / Updated: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose comments and post excerpts for gated content.
The vulnerability exists due to missing authorization in Ghost gated-content comments and post excerpts when handling requests for gated content. A remote attacker can request comments and post excerpts for posts they are not authorized to access to disclose comments and post excerpts for gated content.