Observable discrepancy in Ghost - #VU151105
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to determine the relative ordering of other staff users' hashed passwords.
The vulnerability exists due to an observable discrepancy in the Ghost Admin API when querying staff user information. A remote user can query staff user information to determine the relative ordering of other staff users' hashed passwords.
The issue does not directly disclose password hashes and does not provide a practical path to recovering a password.