PT-2026-67874 · Ghost · Ghost
CVE-2026-70590
·
Published
2026-08-04
·
Updated
2026-08-17
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Ghost versions prior to 6.54.1
Description
Staff-level users can leak the hashed passwords of other staff members through the Ghost Admin API. This could allow an attacker to perform an offline password-guessing attack to potentially take over accounts. However, Device Verification is intended to prevent logins using recovered passwords. The difficulty of such an attack may vary depending on the database used, as leaked hashes might not maintain correct character casing.
Recommendations
Update to version 6.54.1.
Enable Multi-factor Authentication (MFA) for all staff users as a temporary mitigation to prevent unauthorized logins via recovered passwords.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghost