CVE-2026-103268: Tryghost Ghost

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.

Affected products

  • Tryghost Ghost: from 1.0.0, before 6.62.0 (fixed in 6.62.0)

Published 2026-10-01. Last modified 2026-10-01.