CVE-2026-104415
Received Received - Intake

Ghost Admin API Information Disclosure via Staff User Hash Ordering

Vulnerability report for CVE-2026-104415, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password recovery.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tryghost ghost From 0.7.2 (inc) to 6.64.0 (inc)
ghost ghost to 6.64.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ghost (versions 0.7.2 to 6.64.0) allows staff-level users to determine the relative ordering of other staff users' password hashes via the Admin API. It does not expose the hashes directly or enable password recovery, but it reveals hash sequence information.

Detection Guidance

To detect this vulnerability, check the Ghost version installed on your system. If it is between 0.7.2 and 6.63.0, the system is vulnerable. Use commands like 'ghost version' or check the Docker image tag if using a containerized setup.

Impact Analysis

The impact is limited. It only allows staff users to infer hash ordering, not recover passwords. The attack requires low privileges and high complexity, making practical exploitation unlikely. Confidentiality is slightly impacted as hash order may hint at password strength or patterns.

Compliance Impact

This vulnerability has minimal compliance impact. It does not directly expose sensitive data or violate major regulations like GDPR or HIPAA. The low severity and limited confidentiality impact reduce regulatory risk.

Mitigation Strategies

Update Ghost to version 6.64.0 or later immediately. For Docker users, pull the latest official Ghost image. Ghost-CLI users should follow the official update documentation to patch the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104415. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart