CVE-2026-103278: Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe
Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visited by active staff users, enable account takeover through improper input validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.34.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Ghost deployments running versions from 5.8.0 up to, but not including, 6.34.0 are affected. The issue concerns the Ghost admin iframe.
What access does an attacker need?
An attacker needs content publishing privileges so they can create a malicious page. Exploitation also requires an active staff user to visit that page.
What is the likely impact if exploitation succeeds?
A successful attack can allow takeover of the visiting staff user's account. The reported impact includes high confidentiality and integrity impact, with no availability impact indicated.