www.sentinelone.com Critical SQL Injection Vulnerability in Ghost CMS Exploited
Article Content
- •CVE-2026-26980 allows unauthenticated SQL injection in Ghost CMS versions 3.24.0 to 6.19.0.
- •Attackers can extract sensitive information from the database without authentication.
- •Ghost released a patch in version 6.19.1 to address this critical vulnerability.
CVE-2026-26980 is a SQL Injection vulnerability affecting Ghost, a Node.js content management system, allowing unauthenticated attackers to perform arbitrary database reads. The flaw exists in the Content API's slug filter ordering functionality, impacting versions 3.24.0 through 6.19.0. Attackers can exploit this vulnerability without authentication, potentially compromising sensitive user data, including credentials and API keys. The vulnerability was published on February 20, 2026, with a proof of concept released on March 30, 2026. Ghost has released a patch in version 6.19.1, which implements parameterized queries to mitigate the risk. Security professionals are advised to update to the latest version immediately to prevent exploitation. The vulnerability is particularly dangerous due to its ease of exploitation over the network.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ghost and CVE-2026-26980 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed