Ghost CMS Mass Disclosure — 6 CVEs Including CVSS 8.1 Staff Session Bypass
A Ghost staff user with valid credentials can log into any other staff account using only the target's password — bypassing 2FA entirely. CVE-2026-103283 (CVSS 8.1) leads a cluster of six vulnerabilities in Ghost CMS disclosed October 1. Here's the full picture: CVE-2026-103283 (8.1) — Staff session bypass. Any authenticated staff user can impersonate any other staff member with just their password. 2FA does not protect against this.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in