---
id: CVE-2026-103278
title: >-
  Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability
  in the admin iframe that allows attackers to take over staff user accounts
summary: >-
  Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability
  in the admin iframe that allows attackers to take over staff user accounts.
  Attackers with content publishing privileges can craft malicious pages that,
  when vi…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-23
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 5.8.0 < 6.34.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:23.567'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103278'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-5pxf-whwv-g54g'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-5.8.0-before-6.34.0-staff-account-takeover-via-admin-iframe
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.810Z'
---

## Overview

Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visited by active staff users, enable account takeover through improper input validation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
