CVE-2026-103282 UNKNOWN

CVE-2026-103282

Published: 2026-10-01

Description

Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…