CVE-2026-103272: Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API
Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can observe discrepancies in API metadata responses to enumerate staff members and extract sensitive information without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.63.0
Event History
Frequently Asked Questions
Which Ghost deployments are affected?
Ghost versions from 2.10.0 up to, but not including, 6.63.0 are affected. The issue is exposed through the Content API.
Does exploitation require an account or user interaction?
No. The vulnerability can be exploited remotely without authentication or user interaction.
What can an attacker obtain?
An attacker can compare differences in Content API metadata responses to enumerate staff members and extract sensitive user information.
How should teams remediate this issue?
Upgrade Ghost to version 6.63.0 or later. The supplied information does not identify a workaround for deployments that cannot yet be upgraded.