CVE-2026-22594: Ghost has Staff 2FA bypass
Impact A vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA.
Vulnerable versions This vulnerability is present in Ghost v5.105.0 to v5.130.5 to and Ghost v6.0.0 to v6.10.3.
Patches v5.130.6 and v6.11.0 contain a fix for this issue.
References Ghost thanks Sho Odagiri of GMO Cybersecurity by Ierae, Inc. for discovering and disclosing this vulnerability responsibly.
For more information If there are any questions or comments about this advisory, email Ghost at security@ghost.org.
Other sources
Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22594?
CVE-2026-22594 has a significant impact as it allows staff users to bypass email two-factor authentication.
How do I fix CVE-2026-22594?
To fix CVE-2026-22594, upgrade to Ghost version 5.130.6 or 6.11.0.
Which versions are affected by CVE-2026-22594?
CVE-2026-22594 affects Ghost versions from 5.105.0 to 5.130.5 and from 6.0.0 to 6.10.3.
What does CVE-2026-22594 affect specifically?
CVE-2026-22594 affects the two-factor authentication mechanism used by Ghost, allowing for email 2FA skipping.
Who is impacted by CVE-2026-22594?
Staff users of Ghost are directly impacted by CVE-2026-22594 as they can bypass email two-factor authentication.