---
id: CVE-2026-103275
title: >-
  Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in
  the Admin API bulk post and page edit and delete endpoints, which accept
  filters on restricted fields such as authors.password, because of an
  incomplete fix f…
summary: >-
  Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in
  the Admin API bulk post and page edit and delete endpoints, which accept
  filters on restricted fields such as authors.password, because of an
  incomplete fix f…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-203
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 5.42.2 < 6.58.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:23.067'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103275'
references:
  - url: >-
      https://github.com/TryGhost/Ghost/commit/5ef16abe85e9b71ac3f1b1e2cbc462802efe3b5b
    label: disclosure@vulncheck.com
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-ghq6-q78f-2cpg'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-5.42.2-before-6.58.0-password-hash-disclosure
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.809Z'
---

## Overview

Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on restricted fields such as authors.password, because of an incomplete fix for CVE-2026-70590. Staff-level attackers can infer other staff users' password hashes from which filters match and perform offline password-guessing attacks against them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
