CVE-2026-26980 — Ghost — Corrigé dans 6.19.1
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Versions corrigées
Choisissez la version correspondant au produit et à la branche installée.
| Produit | Versions corrigées |
|---|---|
| Ghost | 6.19.1 |
Alerte précoce : exploitation observée
- Exploitation observée depuis le 21 mai 2026
- Pas encore dans le catalogue officiel de la CISA
- Première attaque observée 90 jours après la divulgation
- Confirmée par des capteurs, pas seulement par des signalements
Source : VulnCheck KEV · 7 oct. 2026 30 sept. 2026 25 sept. 2026 22 sept. 2026 15 sept. 2026 11 sept. 2026
Score CVSS9.4 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LType de faiblesse (CWE)CWE-89
Éditeursghost
Produits concernés
| Éditeurs | Produit | Versions |
|---|---|---|
| ghost | ghost | < 6.19.1 |
Articles liés
This product uses the NVD API but is not endorsed or certified by the NVD.
