What is CVE-2026-70589?
CVE-2026-70589 is a vulnerability in Ghost CMS, a Node.js-based platform. In versions 4.22.0 through 6.54.1, a missing validation check allowed users to redeem inactive subscription offers. Affected instances should be immediately updated to version 6.54.1.
Azərbaycanca: CVE-2026-70589, Node.js əsaslı Ghost CMS-də aşkar edilmiş boşluqdur. 4.22.0-dən 6.54.1-ə qədər olan versiyalarda, aktiv olmayan abunə təkliflərinin istifadəsinə imkan verən yoxlama çatışmazlığı mövcuddur. Təsirə məruz qalan sistemləri dərhal 6.54.1 versiyasına yeniləmək tövsiyə olunur.
FAQ2
Which versions of Ghost CMS are affected by CVE-2026-70589?
The vulnerability affects Ghost CMS versions 4.22.0 through 6.54.1.
What action should be taken to remediate CVE-2026-70589?
Affected instances should be immediately updated to version 6.54.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.