---
schema: 1
kind: vulnerability
title: "CVE-2026-26980 — Ghost CMS Content API: unauthenticated blind SQL injection in the slug filter, actively exploited"
headline: "CVE-2026-26980 — Ghost CMS Content API: unauthenticated blind SQL injection in the slug filter, actively exploited"
summary: "Ghost CMS SQL-injection flaw CVE-2026-26980 (CVSS 9.4, unauthenticated) is being mass-exploited in a large-scale ClickFix campaign — XLab/Qianxin documented 700+ compromised self-hosted Ghost sites (including Harvard, Oxford and Auburn university portals and DuckDuckGo); attackers extract the admin API key via blind SQLi, inject JavaScript that serves visitors a fake-Cloudflare \"verify you are human\" lure, and drop loaders/stealers on those who paste the supplied command. Affected 3.24.0–6.19.0; fixed in 6.19.1 (BleepingComputer, 2026-05-24)."
discovered_at: "2026-05-25T05:00:01Z"
event_date: 2026-05-24
run_id: 2026-05-25-d675ef38
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - info-disclosure
  - patch-available
regions:
  - global
sectors:
  - education
  - media
  - technology
entities: []
cves:
  - id: CVE-2026-26980
    cvss: "9.4"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://github.com/advisories/GHSA-w52v-v783-gw97"
    publisher: GitHub Security Advisory GHSA-w52v-v783-gw97
    role: primary
  - url: "https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/"
    publisher: "XLab Qianxin, 2026-05-21"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/"
    publisher: "BleepingComputer, 2026-05-24"
    role: corroborating
closed_sources: []
evidence:
  - quote: "CVE-2026-26980 is an unauthenticated SQL injection (CWE-89) scored CVSS 9.4 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L) in Ghost's Content API."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-25.md
---

CVE-2026-26980 is an unauthenticated SQL injection (CWE-89) scored CVSS 9.4 (`AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L`) in Ghost's Content API. The defect sits in the handling of the `slug` filter parameter, which is interpolated into a raw SQL fragment without parameterisation; a remote attacker with no authentication can perform boolean-based blind extraction of arbitrary database contents — critically the **admin API key**, which then grants full content-management scope over articles, themes and users ([GitHub Security Advisory GHSA-w52v-v783-gw97](https://github.com/advisories/GHSA-w52v-v783-gw97)). Affected versions span Ghost **3.24.0 through 6.19.0** (a roughly three-year release range); the fix shipped in **6.19.1 on 19 February 2026**. Ghost(Pro) cloud instances were patched server-side; self-hosted operators must upgrade themselves, which is the exposed long tail the current campaign targets ([BleepingComputer, 2026-05-24](https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/)).

The CVE clears the § 2 bar on exploitation: SentinelOne documented in-the-wild exploitation as early as 27 February, and XLab confirmed the present large-scale wave (700+ compromised domains) on 21 May ([XLab Qianxin, 2026-05-21](https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/)). Mitigation: upgrade to 6.19.1 or later. Interim compensating controls — block Content API requests whose query string contains `slug:[` (URL-encoded `slug%3A%5B`) at the WAF and restrict or disable the public Content API to trusted origins; the vendor mitigation targets exactly that request pattern. Because the admin API key is the exfiltration target, treat it as compromised on any exposed instance and rotate it after patching, then audit posts and themes for injected JavaScript. Full kill chain and detection in § 5.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-26980 | Ghost CMS (Content API) | 9.4 | n/a | No | Yes (ITW, 700+ sites) | v6.19.1 | [GHSA-w52v-v783-gw97](https://github.com/advisories/GHSA-w52v-v783-gw97) |
