CVE-2026-103273 UNKNOWN

CVE-2026-103273

Published: 2026-10-01

Description

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…