Authentication Bypass Vulnerability in Ghost by Ghost
CVE-2026-103268

8.7HIGH

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103268?

Ghost versions prior to 6.62.0 are susceptible to an authentication bypass flaw that enables users with suspended accounts to reactivate their access. This occurs through a self-service password reset feature, allowing attackers with compromised suspended user credentials to restore their account privileges. Immediate action is recommended to secure your installations and prevent unauthorized access.

Affected Version(s)

Ghost 1.0.0 < 6.62.0

Ghost 6.62.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.