← Back to browse · API

CVE-2026-26980

Severity
CRITICAL
CVSS
9.4
EPSS
0.69332
Risk score
61.87
CISA KEV
No
PoC
Yes
Published
2026-02-20
Modified
2026-05-26
First seen
2026-08-07
Aliases
EUVD-2026-8400, GHSA-W52V-V783-GW97
Products
TryGhost:Ghost 3.24.0, < 6.19.1
Sources
euvd EUVD-2026-8400
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-26980

Description

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

References