Medium severity6.8NVD Advisory· Published Oct 1, 2026
CVE-2026-103279
CVE-2026-103279
Description
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.