Ghost CMS Unauthenticated Admin API Key Theft | MSSP Advisory

High
DateMay 26, 2026
📋Executive Summary
CVE-2026-26980 targets Ghost CMS versions 3.24.0 through 6.19.0, allowing unauthenticated attackers to steal admin API keys without any authentication. Attackers are actively exploiting this vulnerability in large-scale campaigns to gain administrative control over Ghost instances. The vulnerability exposes API keys that grant full administrative privileges to the CMS platform.
⚠️Why It Matters for MSSPs
Your clients running Ghost CMS instances are exposed to complete administrative takeover through stolen API keys, putting their web properties and potentially connected systems at risk. If you manage client websites or have Ghost instances in your own marketing stack, attackers can pivot from compromised CMS admin access into broader network reconnaissance and lateral movement attempts.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.