Sceawere

Vulnerability Detail

CVE-2026-104415UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ghost Admin API Information Disclosure

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
11h ago
Vendor
TryGhost
Product
Ghost
Attack Type
Observable Discrepancy
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password recovery.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-10-02T12:17:11.270Z",
  "pubdate": "2026-10-02T12:17:11.270Z",
  "executiveSummary": "The Ghost platform, specifically versions 0.7.2 through 6.63.1, contains an information disclosure vulnerability within its Admin API.\nThis flaw permits authenticated staff-level users to perform side-channel enumeration concerning the relative ordering of other staff members' password hashes.\nThe vulnerability type is classified as an information disclosure issue, where internal state information is inadvertently exposed through API response patterns.\nThe impact is limited in scope, as the vulnerability does not directly expose plaintext passwords, cryptographic hash values, or facilitate immediate account takeover through password recovery mechanisms.\nThe primary risk implication involves the potential for an internal actor to conduct reconnaissance against the user metadata structure, which could theoretically support more complex, multi-stage attacks if paired with other vulnerabilities.\nExploitation requires the attacker to possess an active, authenticated staff-level session, meaning the attack vector is strictly internal and requires prior unauthorized or legitimate access to the administrative dashboard.",
  "technicalDetails": "The vulnerability resides within the Admin API interface of the Ghost application, specifically affecting how the server handles and returns collection queries involving staff user objects.\nThe root cause is an improper implementation of response ordering and filtering logic, which inadvertently leaks information about the underlying database state regarding user authentication credentials.\nBy issuing specially crafted GET requests to the staff-related API endpoints, a malicious actor can observe the sorting behavior of user entities. When these queries are parameterized, the API reveals metadata that corresponds to the internal database's storage order of sensitive authentication fields, including the hashed password representations.\nAttack flow involves an authenticated staff member iteratively querying the Admin API and observing the response payload structure. Through systematic variation of the request parameters, the attacker can infer the relative ordering of password hashes as they are stored in the backend database. This is a form of side-channel analysis where the latency or ordering of the API result set acts as a proxy for internal database structure.\nThe vulnerable component is the Admin API's request handler, which fails to normalize or sanitize the response output when user-supplied parameters interact with backend sorting routines. This indicates a failure in input validation and output filtering for sensitive administrative endpoints.\nAuthentication is a strict requirement for exploitation; anonymous or unauthenticated users cannot trigger this specific information disclosure. Furthermore, the attacker must hold a 'staff' role, limiting the scope of potential threat actors to those already within the administrative ecosystem of the Ghost instance.\nThe post-exploitation impact is considered low-to-moderate. While the attacker does not gain access to the raw password hashes or the ability to decrypt them, the ability to map the database structure and identify the relative hierarchy of stored hashes can assist in more advanced cryptographic attacks or metadata analysis. It essentially provides a roadmap of the user authentication table that should remain opaque to standard API users.\nThe issue persists across a wide range of versions, specifically starting from 0.7.2 and continuing up to the version 6.64.0 release, where logic corrections were presumably implemented."
}
CVE-2026-104415: Ghost Admin API Information Disclosure (LOW Severity, CVSS: 3.1) | Sceawere