Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions. | |
| Title | Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling | |
| First Time appeared |
Ghost
Ghost ghost |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ghost
Ghost ghost |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T10:42:18.910Z
Reserved: 2026-09-30T10:59:26.443Z
Link: CVE-2026-103283
No data.
Status : Received
Published: 2026-10-01T11:17:24.397
Modified: 2026-10-01T11:17:24.397
Link: CVE-2026-103283
No data.
OpenCVE Enrichment
Updated: 2026-10-01T13:15:08Z
Weaknesses