Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions. | |
| Title | Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling | |
| First Time appeared |
Ghost
Ghost ghost |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:ghost:ghost:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ghost
Ghost ghost |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T10:42:18.910Z
Reserved: 2026-09-30T10:59:26.443Z
Link: CVE-2026-103283
No data.
Status : Received
Published: 2026-10-01T11:17:24.397
Modified: 2026-10-01T11:17:24.397
Link: CVE-2026-103283
No data.
OpenCVE Enrichment
Updated: 2026-10-01T13:15:08Z
-
CWE-613
Insufficient Session Expiration