---
id: CVE-2026-103289
title: >-
  Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the
  comments feature that allows authenticated members to access comments they are
  not authorized to view, resulting in disclosure of restricted comment data.
summary: >-
  Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the
  comments feature that allows authenticated members to access comments they are
  not authorized to view, resulting in disclosure of restricted comment data.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-943
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 5.9.0 < 6.44.1
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:25.360'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103289'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-6q6j-f24j-p477'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-5.9.0-before-6.44.1-authorization-bypass-via-comments
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.814Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-01T13:23:50.517700Z'
---

## Overview

Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
