High severity8.1NVD Advisory· Published Oct 1, 2026
CVE-2026-103283
CVE-2026-103283
Description
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.