CVE-2026-105652: Ghost: Password Hash Ordering Disclosure in Ghost Admin API
Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version 6.64.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.64.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already have a staff-level Ghost account. The issue affects Ghost versions from 0.7.2 through 6.64.0.
What information can an affected user obtain?
A staff-level user can determine the relative ordering of other staff users' hashed passwords through the Ghost Admin API. The hashes themselves are not directly disclosed.
Does this provide a practical way to recover passwords?
No. The available information does not provide a practical path to recovering a password.
What version fixes the issue?
Upgrade Ghost to version 6.64.0, which fixes the issue.