CVE-2026-103268: Tryghost Ghost
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.
Affected products
- Tryghost Ghost: from 1.0.0, before 6.62.0 (fixed in 6.62.0)
Published 2026-10-01. Last modified 2026-10-01.