CVE-2026-103279: Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.34.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Ghost deployments running versions from 3.10.0 before 6.34.0 are affected. An attacker must already possess a valid stolen session cookie for a user account.
Does changing a user's password remove an attacker who has a stolen session cookie?
Not reliably in affected versions. Some existing sessions may remain valid after the password change, allowing continued access to the associated account.
What does an attacker need to exploit this vulnerability?
The attacker needs a stolen session cookie associated with a Ghost user account. The attack is network-reachable but has high attack complexity and requires low privileges.