---
id: CVE-2026-104415
title: >-
  Ghost from 0.7.2 before 6.64.0 contains an information disclosure
  vulnerability in the Admin API that allows staff-level users to determine the
  relative ordering of other staff users' password hashes
summary: >-
  Ghost from 0.7.2 before 6.64.0 contains an information disclosure
  vulnerability in the Admin API that allows staff-level users to determine the
  relative ordering of other staff users' password hashes. Authenticated staff
  users can query …
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-203
vendor: TryGhost
product: Ghost
affected:
  - Ghost >= 0.7.2 < 6.64.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:11.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104415'
references:
  - url: 'https://github.com/TryGhost/Ghost/security/advisories/GHSA-53vv-xm9f-mm82'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghost-0.7.2-before-6.64.0-password-hash-ordering-disclosure-via-admin-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.327Z'
---

## Overview

Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes or enable practical password recovery.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
