CVE-2026-104415 PUBLISHED

Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password recovery.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor TryGhost
Product Ghost
Versions Default: unaffected
  • affected from 0.7.2 to 6.64.0 (excl.)
  • Version 6.64.0 is unaffected

Credits

  • carfeii reporter
  • nhattanhh reporter

References

Problem Types

  • Observable Discrepancy CWE