Ghost CMS discloses six CVEs, including CVSS 8.1 staff session bypass
A cluster of six Ghost CMS vulnerabilities was disclosed on October 1. The most severe, CVE-2026-103283 (CVSS 8.1), lets any authenticated staff user log into another staff account using only the target's password, bypassing 2FA. Fixes shipped in versions 6.34.0 through 6.63.0; users should upgrade to 6.63.0 and rotate credentials.
- CVE-2026-103283 (8.1): 2FA bypass via staff password, fixed in 6.57.1
- CVE-2026-103271 (7.5): unauthenticated access to gated content via Content API, fixed in 6.63.0
- CVE-2026-103266 (7.1): Stripe Checkout abuse and newsletter XSS, fixed in 6.62.0
- CVE-2026-103279 (6.8): session cookies valid after password change, fixed in 6.34.0
Read next
Security