CVE-2026-26980 — Ghost — Fixed in 6.19.1

Critical9.4 Published on Feb 20, 2026

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

Fixed versions

Choose the version for your installed product and release branch.

ProductFixed versions
Ghost6.19.1

Versions stated in the NVD description

Early warning: exploitation observed

  • Exploitation observed since May 21, 2026
  • Not yet in the official CISA catalogue
  • First attack observed 90 days after disclosure
  • Confirmed by sensors, not only by reports

Source: VulnCheck KEV · Oct 7, 2026 Sep 30, 2026 Sep 25, 2026 Sep 22, 2026 Sep 15, 2026 Sep 11, 2026

CVSS score9.4 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Weakness type (CWE)CWE-89
Vendorsghost

Affected products

VendorsProductVersions
ghostghost< 6.19.1

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database