PT-2026-106186 · Ghost · Ghost

·

CVE-2026-105652

·

Published

2026-10-05

·

Updated

2026-10-07

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 0.7.2 through 6.63.x
Description Staff-level users can determine the relative ordering of hashed passwords belonging to other staff users. This issue does not directly disclose the password hashes or provide a practical method for password recovery.
Recommendations Update to version 6.64.0.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105652
GHSA-53VV-XM9F-MM82

Affected Products

Ghost