chiprook
← Security
SecurityOctober 2, 2026, 15:28

Ghost CMS discloses six CVEs, including CVSS 8.1 staff session bypass

A cluster of six Ghost CMS vulnerabilities was disclosed on October 1. The most severe, CVE-2026-103283 (CVSS 8.1), lets any authenticated staff user log into another staff account using only the target's password, bypassing 2FA. Fixes shipped in versions 6.34.0 through 6.63.0; users should upgrade to 6.63.0 and rotate credentials.

Ghost CMS discloses six CVEs, including CVSS 8.1 staff session bypass
#Ghost
Read next
Security

Only one of 225 Anthropic and Glasswing CVEs exploited in the wild

Security

Deno CVE-2026-103473: CVSS 8.1 command injection in node:child_process on Windows

Security

CERT-BUND flags 36 CVEs in 16 Drupal projects, CVSS 9.8

Security

36 open-source device CVEs in September 2026: two already exploited