A flaw in Ghost CMS (versions ≤6.54.0) let any authenticated staff-level user pull the hashed passwords of other staff accounts through a normal API interaction, effectively an information-exposure bug (CWE-200) rather than a remote-exploitable hole. The realistic path to damage is an insider or compromised low-privilege staff account exporting hashes and running an offline cracking attack, which is why the CVSS integrity impact is rated High even though confidentiality is Low — a successful crack could hand an attacker another staff member's full content-editing privileges. Exploitation likelihood is low in practice: EPSS sits at 0.00195 (bottom of the distribution despite the "top 90% most likely" percentile framing), it's not in CISA KEV, CISA rates it SSVC TRACK, and there's no public PoC or Nuclei template. Ghost's built-in Device Verification (email-based step-up on new-device login) blocks most account-takeover attempts even if a password is successfully recovered, and inconsistent hash casing on some databases further raises the bar for crackers. CISOs running self-hosted Ghost should still patch to v6.54.1 promptly, enforce MFA/email 2FA on all staff accounts as a compensating control, and audit staff account activity logs for anomalous cross-user data pulls prior to the patch date.
What is the risk?
Medium severity (CVSS 4.8) reflects a narrow exploitation path: the attacker must already hold a valid staff-level Ghost account (PR:H), the attack requires high complexity (AC:H) and user interaction (UI:R), meaning this is realistically an insider-threat or compromised-low-privilege-account scenario rather than something exploitable by an anonymous internet attacker. The confidentiality impact is capped at Low because only password hashes (not plaintext) are exposed, but the Integrity:High rating captures the downstream risk — a cracked hash grants full staff-level content control. Exploitation probability is low today (EPSS 0.00195, no KEV listing, no public exploit code, SSVC TRACK), but the risk compounds for any Ghost instance with weak staff password hygiene or MFA not enabled, since Device Verification is the only real backstop preventing account takeover from a recovered password.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Microsoft APM | npm | < 6.54.1 | 6.54.1 |
Do you use Microsoft APM? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade to Ghost v6.54.1 or later immediately — Docker users should pull the updated official image and follow Ghost's documented Docker update process; Ghost-CLI installs should run the standard
ghost updateworkflow. As a compensating control until patched, enforce Multi-Factor Authentication (email-based Device Verification / 2FA) on every staff account, since this is explicitly called out by Ghost as blocking account takeover even if a password hash is successfully cracked. Rotate staff passwords post-patch as a precaution, especially for any accounts that may have been active before the fix. For detection, review Ghost admin/API access logs for staff accounts making unusual bulk queries against other-user data prior to the v6.54.1 upgrade date, and monitor for anomalous login attempts flagged by Device Verification.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-70590?
A flaw in Ghost CMS (versions ≤6.54.0) let any authenticated staff-level user pull the hashed passwords of other staff accounts through a normal API interaction, effectively an information-exposure bug (CWE-200) rather than a remote-exploitable hole. The realistic path to damage is an insider or compromised low-privilege staff account exporting hashes and running an offline cracking attack, which is why the CVSS integrity impact is rated High even though confidentiality is Low — a successful crack could hand an attacker another staff member's full content-editing privileges. Exploitation likelihood is low in practice: EPSS sits at 0.00195 (bottom of the distribution despite the "top 90% most likely" percentile framing), it's not in CISA KEV, CISA rates it SSVC TRACK, and there's no public PoC or Nuclei template. Ghost's built-in Device Verification (email-based step-up on new-device login) blocks most account-takeover attempts even if a password is successfully recovered, and inconsistent hash casing on some databases further raises the bar for crackers. CISOs running self-hosted Ghost should still patch to v6.54.1 promptly, enforce MFA/email 2FA on all staff accounts as a compensating control, and audit staff account activity logs for anomalous cross-user data pulls prior to the patch date.
Is CVE-2026-70590 actively exploited?
No confirmed active exploitation of CVE-2026-70590 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-70590?
Upgrade to Ghost v6.54.1 or later immediately — Docker users should pull the updated official image and follow Ghost's documented Docker update process; Ghost-CLI installs should run the standard `ghost update` workflow. As a compensating control until patched, enforce Multi-Factor Authentication (email-based Device Verification / 2FA) on every staff account, since this is explicitly called out by Ghost as blocking account takeover even if a password hash is successfully cracked. Rotate staff passwords post-patch as a precaution, especially for any accounts that may have been active before the fix. For detection, review Ghost admin/API access logs for staff accounts making unusual bulk queries against other-user data prior to the v6.54.1 upgrade date, and monitor for anomalous login attempts flagged by Device Verification.
What systems are affected by CVE-2026-70590?
This vulnerability affects the following AI/ML architecture patterns: content management / publishing backend, AI content pipelines using Ghost as the CMS layer for newsletter or blog automation.
What is the CVSS score for CVE-2026-70590?
CVE-2026-70590 has a CVSS v3.1 base score of 4.8 (MEDIUM). The EPSS exploitation probability is 0.32%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0012 Valid Accounts AML.T0106 Exploitation for Credential Access Compliance Controls Affected
What are the technical details?
Original Advisory
### Impact Any staff-level user was able to leak the hashed passwords of other staff users. An offline password-guessing attack against the hashes could lead to account takeover if successful, but [Device Verification](https://docs.ghost.org/security#device-verification) should have prevented an attacker from logging in with a recovered password. Depending on the database used, leaked hashes may not have had the correct casing for all characters, increasing the difficulty of a password-guessing attack. ### Vulnerable versions This vulnerability is present in Ghost versions v6.54.0 and earlier. ### Patches v6.54.1 contains a fix for this issue. ### How to update For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost). If your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://docs.ghost.org/update). ### Workarounds If upgrading immediately is not possible, ensure all staff users have [Multi-factor Authentication](https://docs.ghost.org/security#email-2fa) (MFA) enabled. This will help prevent an attacker from logging in with any passwords that are successfully recovered from the leaked hashes. ### References Ghost thanks Chapman Schleiss for disclosing this vulnerability responsibly. ### For more information If you have any questions or comments about this advisory, email us at [security@ghost.org](mailto:security@ghost.org).
Exploitation Scenario
An attacker who has already obtained low-privilege staff credentials for a Ghost instance (via phishing, credential stuffing, or an insider with grudge access) uses that legitimate session to query the vulnerable staff-management endpoint and retrieve the password hashes of higher-privileged staff or admin accounts. The attacker exports these hashes offline and runs a dictionary/brute-force cracking attack (complicated somewhat by potential hash-casing inconsistencies depending on the backing database). If a password is successfully recovered, the attacker attempts to log in as the higher-privileged user — but Ghost's Device Verification challenges the new device/location with an email confirmation step, which in most cases blocks the takeover unless the attacker also controls the target's email account.
Weaknesses (CWE)
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Primary
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor: The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- [Architecture and Design] Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:N References
Timeline
Related Vulnerabilities
CVE-2026-46858 9.1 Oracle APM: unauthenticated write/DoS via JVM Diagnostics
Same package: apm CVE-2026-57947 8.5 Pinpoint APM: SSRF via alarm webhook registration
Same package: apm CVE-2026-45539 7.4 Microsoft APM: symlink attack leaks host files in agent deps
Same package: apm CVE-2026-57948 6.8 Pinpoint: insecure JWT cookie enables session hijacking
Same package: apm CVE-2026-49835 5.9 Sigstore TSA: unbounded metrics label DoS
Same package: apm