HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-103283 — Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability tha...
·Source: NIST NVD
Updated:
Executive Summary
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.
Analysis
Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions. CVSS Score: 8.1. Published: 2026-10-01T11:17:24.397.