CVE-2026-26980 — Ghost — Corretto in 6.19.1
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Versioni corrette
Scegli la versione relativa al prodotto e al ramo installato.
| Prodotto | Versioni corrette |
|---|---|
| Ghost | 6.19.1 |
Preallarme: sfruttamento osservato
- Sfruttamento osservato dal 21 mag 2026
- Non ancora nel catalogo ufficiale CISA
- Primo attacco osservato 90 giorni dopo la divulgazione
- Confermata dai sensori, non solo da segnalazioni
Fonte: VulnCheck KEV · 7 ott 2026 30 set 2026 25 set 2026 22 set 2026 15 set 2026 11 set 2026
Punteggio CVSS9.4 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:LTipo di debolezza (CWE)CWE-89
Vendorghost
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| ghost | ghost | < 6.19.1 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
