CVE-2026-105652
Received Received - Intake

Staff Password Hash Order Disclosure in Ghost CMS

Vulnerability report for CVE-2026-105652, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version 6.64.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 0.7.2, < 6.64.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ghost CMS allows staff-level users to determine the relative ordering of other staff users' hashed passwords without directly exposing the hashes. It does not enable password recovery but reveals password hash order, which could aid in targeted attacks. The issue exists in versions from 0.7.2 to 6.64.0 and was patched in 6.64.0.

Detection Guidance

This vulnerability is specific to Ghost CMS versions 0.7.2 through 6.64.0 and involves staff-level users being able to determine the relative ordering of other staff users' hashed passwords. Detection requires checking the Ghost version in use. Use the command: ghost version in your Ghost CLI environment or check the version in the Ghost admin panel under Settings > About Ghost. If the version is between 0.7.2 and 6.64.0, the system is vulnerable.

Impact Analysis

The impact is limited due to high attack complexity and low privileges required. An attacker could use this to infer password hash order, potentially aiding brute-force or rainbow table attacks. However, direct password exposure is not possible. The vulnerability primarily affects confidentiality by leaking metadata about password hashes.

Compliance Impact

This vulnerability does not directly expose password hashes or enable password recovery, so it does not directly violate GDPR or HIPAA requirements for protecting personal data. However, it could indirectly impact compliance by allowing staff-level users to infer the relative ordering of other staff users' hashed passwords, which may raise concerns about data confidentiality and access controls under these regulations.

Mitigation Strategies

Update Ghost to version 6.64.0 or later immediately. For Docker users, pull the latest official Ghost image and redeploy. Ghost-CLI users should run ghost update to upgrade. After updating, verify the version again to confirm the patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105652. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart