CVE-2026-103279 HIGH

CVE-2026-103279: Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass

Vendor Tryghost
Product Ghost
Weakness CWE-613 · Insufficient session expiration
Published October 1, 2026
Last update October 6, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.

Key dates

02Disclosure timeline

October 1, 2026 CVE published
October 6, 2026 Record updated