Observable discrepancy in Ghost - #VU151105

 

Observable discrepancy in Ghost - #VU151105

Published: September 18, 2026


Vulnerability identifier: #VU151105
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to determine the relative ordering of other staff users' hashed passwords.

The vulnerability exists due to an observable discrepancy in the Ghost Admin API when querying staff user information. A remote user can query staff user information to determine the relative ordering of other staff users' hashed passwords.

The issue does not directly disclose password hashes and does not provide a practical path to recovering a password.


Affected software

Ghost

Remediation

Install security update from vendor's website.

Ghost - update to 6.64.0

External References

Related Security Bulletins