Description
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
Published: 2026-10-01
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass – Impersonation of staff accounts
Action: Immediate Patch
AI Analysis

Impact

Ghost versions 6.20.0 up to but not including 6.57.1 contain a flaw in session management that lets any authenticated staff user log in as any other staff member by supplying only a password. This bypasses two‑factor authentication and permits the attacker to assume another staff member’s identity, thereby gaining access to administrative functions. The vulnerability is classified as CWE-613 – session fixation or authentication bypass. The CVSS score of 8.6 indicates substantial impact on confidentiality, integrity, and availability of the system.

Affected Systems

The affected systems are Ghost content management platforms released by TryGhost, specifically all versions from 6.20.0 through 6.56.x. Users running later versions are not impacted.

Risk and Exploitability

The high CVSS score reflects both the severity of the issue and the ease of exploitation once staff credentials are known. EPSS data is unavailable, but the lack of a list in CISA’s KEV catalog does not diminish the risk; attackers with valid staff credentials can abuse the flaw immediately. The likely attack vector requires the attacker to be an authenticated staff user, after which they can manipulate the session payload to impersonate other staff accounts.

Generated by OpenCVE AI on October 1, 2026 at 14:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.57.1 or newer, which contains the session handling fix.
  • If an upgrade cannot be performed immediately, enforce multi‑factor authentication for all staff accounts and enforce strong password policies to mitigate credential compromise.
  • Continuously monitor logs for anomalous session changes or staff account switching that could indicate exploitation of the flaw.

Generated by OpenCVE AI on October 1, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
Title Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling
First Time appeared Ghost
Ghost ghost
Weaknesses CWE-613
CPEs cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:*
Vendors & Products Ghost
Ghost ghost
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:42:18.910Z

Reserved: 2026-09-30T10:59:26.443Z

Link: CVE-2026-103283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:24.397

Modified: 2026-10-01T15:06:17.330

Link: CVE-2026-103283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration