THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jm22-3w23-5q7w (medium) — Ghost: Blind Password Hash Disclosure in Ghost Admin API

[GHSA] GHSA-jm22-3w23-5q7w (medium) — Ghost: Blind Password Hash Disclosure in Ghost Admin API

highgithub_advisoriesPublished 2026-08-04

GHSA-jm22-3w23-5q7w Severity: medium CVE: CVE-2026-70590

Ghost: Blind Password Hash Disclosure in Ghost Admin API

### Impact

Any staff-level user was able to leak the hashed passwords of other staff users. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jm22-3w23-5q7w