CVE-2026-103284: Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback
Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.57.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs staff privileges in Ghost. The vulnerable Admin Feedback endpoint can then be queried to retrieve sensitive member data without the required authorization checks.
Which deployments are affected?
Ghost versions from 5.125.1 before 6.57.1 are affected. The provided information does not identify any configuration prerequisite beyond having the Admin Feedback endpoint available to a staff user.
What is the immediate mitigation if an upgrade cannot be performed?
Restrict and review staff access, because staff privileges are required for exploitation. Remove staff access from accounts that do not need it and investigate use of the Admin Feedback endpoint by existing staff accounts.