Description
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
Published: 2026-10-01
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Session Invalidation Bypass
Action: Update Immediately
AI Analysis

Impact

Ghost versions from 3.10.0 up to 6.33.9 do not completely invalidate session data after a password change, enabling an attacker who has obtained a session cookie to continue accessing the user account even after a password reset. This flaw allows persistent unauthorized access and threatens confidentiality and integrity of user data by permitting attackers to maintain footholds in compromised accounts. The weakness is a classic session invalidation bypass, classified as CWE‑613.

Affected Systems

The affected product is Ghost content management system from vendor TryGhost. Versions starting with 3.10.0 and older than 6.34.0 are vulnerable; any installations using 3.10.0 through 6.33.9 are at risk.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity impact. The EPSS score is not available, so the current probability of exploitation cannot be quantified, but the flaw is in the session management layer, which is typically accessible via HTTP. Because the vulnerability does not require privileged access to exploit, attackers with reasonable network visibility or those who have stolen a session cookie can actively abuse it. The issue is not listed in the CISA KEV catalog, but it remains a serious risk for sites that rely on Ghost for user authentication. The likely attack vector is a stolen or intercepted session cookie combined with a password reset mechanism that does not clear all session identifiers.

Generated by OpenCVE AI on October 1, 2026 at 14:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Ghost release, at least 6.34.0, to fix the session invalidation bug
  • After updating, manually log out all active sessions or use the administrative interface to force session invalidation for all users
  • Ensure that password change processes include complete session cleanup and validate that session cookies are revoked immediately after a successful credential update

Generated by OpenCVE AI on October 1, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
Title Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-613
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:42:16.054Z

Reserved: 2026-09-30T10:59:00.638Z

Link: CVE-2026-103279

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:23.743

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration