CVE-2026-103283: Tryghost Ghost

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.

Affected products

  • Tryghost Ghost: from 6.20.0, before 6.57.1 (fixed in 6.57.1)

Published 2026-10-01. Last modified 2026-10-06.