CVE-2026-22595

HIGH

Ghost < 5.130.6 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens for Admin/Owner-role users would have had access to these endpoints. This issue has been patched in versions 5.130.6 and 6.11.0.

Scores

CVSS v3 8.1
EPSS 0.0004
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
ghost/ghost 5.121.0 - 5.130.6
npm/ghost 6.0.0 - 6.11.0npm
Published Jan 10, 2026
Tracked Since Feb 18, 2026