What is CVE-2026-26980?
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.
Affected product
Ghost
Remediation Steps
- Apply the latest Ghost CMS security update that addresses the SQL injection vulnerability
- Audit Ghost instances for injected malicious JavaScript in content
- Review user activity logs for signs of compromise or unauthorized modifications
- Implement Content Security Policy (CSP) headers to mitigate JavaScript injection impact
References
- https://github.com/TryGhost/Ghost/commit/30868d632b2252b638bc8a4c8ebf73964592ed91
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-w52v-v783-gw97
- https://github.com/TryGhost/Ghost/releases/tag/v6.19.1
- https://nvd.nist.gov/vuln/detail/CVE-2026-26980
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Coverage on defend.network
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.