Description
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.
Published: 2026-10-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass (Privilege Escalation)
Action: Immediate Patch
AI Analysis

Impact

Ghost versions before 6.62.0 have an authentication bypass that lets a suspended staff user reset their password and reactivate the account. The attacker regains original privileges, providing a path to full control of the site. The flaw is a classic authentication bypass (CWE-862).

Affected Systems

TryGhost's Ghost content management system, all releases prior to 6.62.0, including Ghost 1.0.0 through 6.61.x, is affected. The vulnerability resides in the self‑service password‑reset flow for suspended staff accounts.

Risk and Exploitability

The CVSS score of 8.7 indicates high impact. No EPSS data is available, but the flaw can be exploited via the public password‑reset interface, so remote attackers can use the flaw if they have evidence of a suspended staff credential. The vulnerability is not listed in the CISA KEV catalog, but its high severity means it should be treated as a high‑priority risk.

Generated by OpenCVE AI on October 1, 2026 at 14:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.62.0 or later to apply the official fix that blocks password reset for suspended accounts.
  • Before the upgrade, disable the self‑service password‑reset feature for suspended accounts via configuration changes or access‑control rules to prevent reactivation.
  • After the upgrade, audit the user database to identify all suspended staff accounts and confirm they cannot reset passwords, then re‑suspend any users that should remain inactive.

Generated by OpenCVE AI on October 1, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.
Title Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-862
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:33:19.164Z

Reserved: 2026-09-30T10:58:33.573Z

Link: CVE-2026-103268

cve-icon Vulnrichment

Updated: 2026-10-01T13:33:15.635Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:22.073

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses