ExploitMatch
Back

CVE-2026-103274

Monitor on ThreatCluster

Description

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, bypassing privacy settings.