CVE-2026-26980
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/TryGhost/Ghost/releases/tag/v6.19.1, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26980.json, https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97, https://nvd.nist.gov/vuln/detail/CVE-2026-26980, https://github.com/TryGhost/Ghost/commit/30868d632b2252b638bc8a4c8ebf73964592ed91
