CVE-2026-104415: Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API
Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password recovery.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.64.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs authenticated staff-level access to the Ghost Admin API. Unauthenticated users are not described as able to exploit it.
What information can a staff user obtain through the vulnerable API?
A staff user can infer the relative ordering of other staff users' password hashes. The issue does not directly disclose password hashes or provide a practical method for password recovery.
Which Ghost versions are affected?
Ghost versions from 0.7.2 up to, but not including, 6.64.0 are affected.