THREAT OPS › Threat News › [GHSA] GHSA-jm22-3w23-5q7w (medium) — Ghost: Blind Password Hash Disclosure in Ghost Admin API
[GHSA] GHSA-jm22-3w23-5q7w (medium) — Ghost: Blind Password Hash Disclosure in Ghost Admin API
GHSA-jm22-3w23-5q7w Severity: medium CVE: CVE-2026-70590
Ghost: Blind Password Hash Disclosure in Ghost Admin API
### Impact
Any staff-level user was able to leak the hashed passwords of other staff users. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have
MITRE ATT&CK techniques
- Multi-Factor AuthenticationT1556.006
Indicators of compromise
- CVE-2026-70590cve
- https://docs.ghost.org/security#device-verificationurl
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- https://docs.ghost.org/security#email-2faurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-jm22-3w23-5q7w