HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-103283 — Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability tha...

·Source: NIST NVD

Updated:

Executive Summary

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions.

Analysis

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only the password, bypassing two-factor authentication. Attackers with valid staff credentials can exploit improper session management to impersonate other staff members and gain unauthorized access to administrative functions. CVSS Score: 8.1. Published: 2026-10-01T11:17:24.397.

Indicators of Compromise (1)

CVE (1)
CVE-2026-103283
Source Attribution

Originally published by NIST NVD on Oct 1, 2026. Verified by: NIST.

Related Threats