---
id: CVE-2026-103284
title: >-
  Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure
  vulnerability in the Admin Feedback endpoint that allows unauthorized staff
  users to access member data
summary: >-
  Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure
  vulnerability in the Admin Feedback endpoint that allows unauthorized staff
  users to access member data. Attackers with staff privileges can query the
  feedback e…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-863
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 5.125.1 < 6.57.1
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:24.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103284'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-vm82-r49m-224q'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-5.125.1-before-6.57.1-information-disclosure-via-feedback
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.812Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-01T13:30:35.262552Z'
---

## Overview

Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. Attackers with staff privileges can query the feedback endpoint to retrieve sensitive member information without proper authorization checks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
