CVE-2026-103269: Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts
Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not have access to (gated content).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.62.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Ghost deployments running versions from 5.3.0 up to, but not including, 6.62.0 are affected. Exposure concerns sites that use gated content and have authenticated site members.
What access does an attacker need?
An attacker must be authenticated as a site member. No additional privileges or user interaction are indicated.
What information can be accessed?
The issue permits an authenticated site member to read excerpts of posts that they are not authorized to access. The available information indicates confidentiality impact only; it does not indicate that full post content can be read or modified.
How can I remediate this issue?
Upgrade Ghost to version 6.62.0 or later. The provided information does not identify a workaround for deployments that cannot immediately upgrade.