Authentication Bypass Vulnerability in Ghost by Ghost
CVE-2026-103268
8.7HIGH
What is CVE-2026-103268?
Ghost versions prior to 6.62.0 are susceptible to an authentication bypass flaw that enables users with suspended accounts to reactivate their access. This occurs through a self-service password reset feature, allowing attackers with compromised suspended user credentials to restore their account privileges. Immediate action is recommended to secure your installations and prevent unauthorized access.
Affected Version(s)
Ghost 1.0.0 < 6.62.0
Ghost 6.62.0
