CVE-2026-103273: Tryghost Ghost

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with staff credentials can leverage tokens to edit posts beyond their assigned privilege level.

Affected products

  • Tryghost Ghost: from 4.3.0, before 6.58.0 (fixed in 6.58.0)

Published 2026-10-01. Last modified 2026-10-01.