CVE-2026-103273
Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.
- Published Oct 1, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available