Description

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

INFO

Published Date :

2026-02-20T01:00:51.633Z

Last Modified :

2026-02-20T15:35:37.895Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-26980 vulnerability.

Vendors Products
Ghost
  • Ghost

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact