CVE-2026-26980 — Ghost — Fixed in 6.19.1
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Fixed versions
Choose the version for your installed product and release branch.
| Product | Fixed versions |
|---|---|
| Ghost | 6.19.1 |
Early warning: exploitation observed
- Exploitation observed since May 21, 2026
- Not yet in the official CISA catalogue
- First attack observed 90 days after disclosure
- Confirmed by sensors, not only by reports
Source: VulnCheck KEV · Oct 7, 2026 Sep 30, 2026 Sep 25, 2026 Sep 22, 2026 Sep 15, 2026 Sep 11, 2026
CVSS score9.4 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LWeakness type (CWE)CWE-89
Vendorsghost
Affected products
| Vendors | Product | Versions |
|---|---|---|
| ghost | ghost | < 6.19.1 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
