What is CVE-2026-70590?
In Ghost CMS versions prior to 6.54.1, any staff-level user could leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against these hashes could lead to account takeover, though Device Verification mitigates this risk. Affected systems should be immediately upgraded to version 6.54.1 or later.
Azərbaycanca: Ghost CMS-in 6.54.1 versiyasından əvvəlki versiyalarında istənilən "staff" səviyyəli istifadəçi Ghost Admin API vasitəsilə digər işçilərin heşlənmiş parollarını sızdıra bilər. Bu heşlər üzərində oflayn parol təxmini hücumu nəticəsində hesab ələ keçirilə bilər, lakin Cihaz Doğrulama (Device Verification) funksiyası bu riski azaldır. Təsirə məruz qalan sistemlərdə dərhal 6.54.1 və ya daha yuxarı versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which user level in Ghost CMS could leak other staff users' password hashes through CVE-2026-70590?
Any staff-level user could leak the hashed passwords of other staff users through the Ghost Admin API.
Which feature mitigates the account takeover risk in systems affected by CVE-2026-70590?
Device Verification mitigates the risk of account takeover from an offline password-guessing attack against the leaked hashes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.