CVE-2026-103282: Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token
Published Oct 1, 2026
·Updated
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.
Affected Software
1 affected component
Ghost Ghost>=0.5.0<6.23.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.23.0
Event History
Oct 1, 2026
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can this be exploited remotely without user interaction?
Yes. The CVSS vector indicates network-based exploitation (AV:N) and no user interaction is required (UI:N).
2
What does an attacker need to exploit the issue?
The attacker needs low privileges and a staff invitation token, then must submit concurrent invitation-acceptance requests using that same token.