CVE-2026-103289: Improper Neutralization of Special Elements in Data Query Logic in TryGhost Ghost
Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.
AI Analysis
Technical Summary
CVE-2026-103289 describes an input validation issue in the TryGhost Ghost blogging platform's comments feature affecting versions >=5.9.0 and <6.44.1. Authenticated members can exploit this flaw to bypass access controls and retrieve comments that are restricted, resulting in unauthorized data disclosure. The vulnerability does not require user interaction and has a low attack complexity, but requires privileges of an authenticated member.
Potential Impact
Exploitation of this vulnerability leads to disclosure of restricted comment data to unauthorized authenticated users. This could compromise confidentiality of sensitive information contained in comments that should be access-controlled. There is no indication of privilege escalation, denial of service, or code execution.
Mitigation Recommendations
A fix is available in Ghost version 6.44.1 and later. Users should upgrade to version 6.44.1 or above to remediate this vulnerability. No other mitigation or temporary workaround is indicated.
CVE-2026-103289: Improper Neutralization of Special Elements in Data Query Logic in TryGhost Ghost
Description
Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.
CVSS v4.0
Score 7.1high
Affected software
TryGhost
Ghost
pkg:github/tryghost/GhostRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103289 describes an input validation issue in the TryGhost Ghost blogging platform's comments feature affecting versions >=5.9.0 and <6.44.1. Authenticated members can exploit this flaw to bypass access controls and retrieve comments that are restricted, resulting in unauthorized data disclosure. The vulnerability does not require user interaction and has a low attack complexity, but requires privileges of an authenticated member.
Potential Impact
Exploitation of this vulnerability leads to disclosure of restricted comment data to unauthorized authenticated users. This could compromise confidentiality of sensitive information contained in comments that should be access-controlled. There is no indication of privilege escalation, denial of service, or code execution.
Mitigation Recommendations
A fix is available in Ghost version 6.44.1 and later. Users should upgrade to version 6.44.1 or above to remediate this vulnerability. No other mitigation or temporary workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-30T10:59:26.443Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abe748ba43b0b3b89bd1c82
Added to database: 10/01/2026, 14:56:11 UTC
Last enriched: 10/01/2026, 15:18:29 UTC
Last updated: 10/02/2026, 03:06:36 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.