CVE-2026-103288
Received Received - Intake

Ghost Comment Like Feature Authorization Bypass

Vulnerability report for CVE-2026-103288, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ghost ghost From 5.9.0 (inc) to 6.44.1 (exc)
tryghost ghost From 5.9.0 (inc) to 6.44.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Ghost's comment like feature. An authenticated user can delete likes or dislikes on comments that belong to other users without proper authorization. This affects versions from 5.9.0 before 6.44.1.

Detection Guidance

This vulnerability involves an authorization bypass in Ghost's comment like feature. To detect it, check Ghost's access logs for unusual deletion activity on comment likes/dislikes by authenticated members. Look for patterns where users modify engagement data not belonging to them. No specific commands are provided in the context.

Impact Analysis

This flaw allows unauthorized users to manipulate comment engagement data, potentially altering the perceived popularity or relevance of comments. This could mislead readers and affect community trust in the platform.

Compliance Impact

This vulnerability allows unauthorized modification of comment engagement data, which could impact data integrity. For GDPR, this may affect compliance with Article 5 (integrity and confidentiality) if personal data is altered without authorization. For HIPAA, unauthorized changes to user engagement data could violate integrity requirements under the Security Rule.

Mitigation Strategies

Upgrade Ghost to version 6.44.1 or later to patch the input validation flaw. If immediate upgrade isn't possible, disable the comment like feature temporarily or restrict member permissions to prevent unauthorized modifications. Monitor comment engagement data for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103288. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart