CVE-2026-103273
EUVD-2026-9066601.10.2026, 11:17
Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.