HIGH 8.7 NVD
CVE-2026-103268
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.
References
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-q734-xjgc-vpj9
- https://www.vulncheck.com/advisories/ghost-1.0.0-before-6.62.0-suspension-bypass-via-passw
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.