CVE-2026-103273: Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token
Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.58.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs valid lower-privilege Ghost staff credentials and a staff token. Unauthenticated attackers are not indicated by the available information.
What is the impact of successful exploitation?
A lower-privilege staff user can bypass post-editing restrictions and edit posts beyond the permissions assigned to their role. The reported impact is limited to integrity; confidentiality and availability impacts are not identified.
Which versions need remediation?
Ghost versions from 4.3.0 up to, but not including, 6.58.0 are affected. Updating to 6.58.0 or later addresses the affected version range.