CVE-2026-70590
Received Received - Intake

Staff Password Hash Leak in Ghost CMS

Vulnerability report for CVE-2026-70590, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. This issue is fixed in version 6.54.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ghost ghost to 6.54.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ghost CMS allows any staff-level user to access and leak hashed passwords of other staff users through the Ghost Admin API. The issue was present before version 6.54.1 and could enable offline password-guessing attacks to potentially take over accounts.

Detection Guidance

To detect this vulnerability, check if your Ghost CMS version is below 6.54.1. Use the command: ghost version. If the version is older, update immediately. Additionally, review staff user accounts for unusual activity or unauthorized access attempts.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized access to staff accounts, potential data breaches, and account takeovers. Attackers might recover passwords through offline attacks and bypass device verification in some cases.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing staff user hashed passwords through the Ghost Admin API. Unauthorized access to such credentials may lead to privacy violations under GDPR or breaches of protected health information under HIPAA if attackers gain access to sensitive data.

Mitigation Strategies

Upgrade Ghost to version 6.54.1 or later to address the password leak vulnerability. Review staff accounts for unauthorized access and rotate passwords as a precaution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70590. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart