Loading
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Use CWE-89, Ghost vendor hub and Ghost product page to widen CVE-2026-26980 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-34451, CVE-2026-24778 and CVE-2024-34448 for nearby disclosures in the same product family.