CVE-2026-103283 HIGH

CVE-2026-103283: Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling

Vendor Tryghost
Product Ghost
Weakness CWE-613 · Insufficient session expiration
Published October 1, 2026
Last update October 6, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.

Key dates

02Disclosure timeline

October 1, 2026 CVE published
October 6, 2026 Record updated