CVE-2026-103282
EUVD-2026-9067501.10.2026, 11:17
Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single invite token. Attackers can exploit this race condition by submitting concurrent requests with the same invitation token to create duplicate user accounts.
Awaiting analysis
This vulnerability is currently awaiting analysis.