CVE-2026-103283: Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.57.1
Event History
Frequently Asked Questions
Which deployments are affected?
Ghost versions 6.20.0 through versions before 6.57.1 are affected. Deployments running 6.57.1 or later are not identified as affected by the provided information.
What does an attacker need to exploit this issue?
The attacker needs valid credentials for a staff account and the password of the staff user they intend to impersonate. No user interaction is required.
Does two-factor authentication prevent the impersonation?
No. The vulnerability allows an authenticated staff user to bypass two-factor authentication when logging in as another staff user using that user's password.
How can we determine whether we are exposed?
Check the deployed Ghost version and identify whether it is 6.20.0 or later but earlier than 6.57.1. Also assess whether staff accounts and their passwords may be accessible to other authenticated staff users.