Sceawere
Vulnerability Detail
CVE-2026-105652UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ghost Staff User Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 1h ago
- Vendor
- TryGhost
- Product
- Ghost
- Attack Type
- CWE-203: Observable Discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version 6.64.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-10-05T20:17:14.180Z",
"pubdate": "2026-10-05T20:17:14.180Z",
"executiveSummary": "A vulnerability exists in Ghost CMS, ranging from version 0.7.2 through 6.64.0, which allows authenticated staff-level users to perform side-channel analysis on the relative ordering of other staff members' hashed passwords.\nThis vulnerability is classified as an information disclosure issue, specifically involving the leakage of metadata regarding stored password hashes.\nWhile the vulnerability does not result in the direct exfiltration of password hashes or provide an immediate vector for plaintext recovery, it permits an attacker to observe systematic differences in the internal state of the application's authentication data.\nThe scope of impact is limited to the administrative backend, requiring an attacker to already possess legitimate staff-level credentials to conduct the observation.\nThe risk implication centers on the potential for advanced adversaries to use this metadata as part of a reconnaissance phase, potentially correlating user accounts or identifying specific patterns in system-wide authentication storage.\nThe vulnerability is resolved in version 6.64.0, which remediates the underlying logic responsible for the disclosure.",
"technicalDetails": "The root cause of this vulnerability lies in an improper handling of sensitive data structures during API queries initiated by staff-level users. Within the Ghost CMS administrative interface, specific request patterns permitted authenticated users to deduce the relative sequence or collation order of password hashes stored in the backend database.\nThe vulnerability occurs within the user management or profile retrieval components of the application. By analyzing the responses of authenticated endpoints, a malicious actor can observe subtle behavioral variations that correlate with the database's internal ordering of password hashes. This is essentially a side-channel mechanism where the relative arrangement of records is exposed via predictable application responses.\nThe attack flow requires the adversary to maintain an active, authenticated session as a staff user within the Ghost instance. The attacker interacts with specific, likely internal-facing, API endpoints that query user metadata. By systematically crafting requests and monitoring the output, the attacker can establish a baseline for how different users' password hashes are ordered or indexed by the database. The system inadvertently leaks information about the underlying data arrangement that should remain encapsulated from the user interface level.\nThis issue is strictly limited to authenticated environments. Because the vulnerability is confined to the staff-level permission tier, an unauthenticated remote attacker cannot trigger the disclosure. The attack is restricted to those already having valid administrative access, making this a vertical privilege escalation or reconnaissance vector rather than an external exploit.\nWhile the disclosure does not directly expose the cryptographic materials, the ability to determine the relative ordering provides an adversary with verifiable information about the state of the user database. If an attacker identifies a specific pattern, they could potentially infer details about how accounts were created, the sequence of password updates, or identify unique identifiers linked to specific, targeted staff accounts. This information, while not immediately devastating, reduces the entropy and opacity of the system's security architecture, potentially aiding in further targeted attacks or account-takeover scenarios if combined with other vulnerabilities. The flaw persists across a significant range of Ghost versions (0.7.2 to 6.64.0) until the final patch in 6.64.0 corrected the logical processing of these user-specific requests."
}