CVE-2026-103289: Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments
Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.44.1
Event History
Frequently Asked Questions
Which deployments are affected?
Ghost versions from 5.9.0 before 6.44.1 are affected. The issue is in the comments feature.
What does an attacker need to exploit this issue?
An attacker needs to be an authenticated Ghost member. No user interaction is required, and the issue is remotely exploitable.
What information could be exposed?
An authenticated member may be able to access comments they are not authorized to view, disclosing restricted comment data. The provided information does not indicate an impact on data integrity or availability.
How can I determine whether my site is at risk?
Check whether the Ghost instance is running a version from 5.9.0 through versions before 6.44.1 and has the comments feature in use. The provided information does not describe a detection method for identifying prior exploitation.