Session Fixation Vulnerability in Ghost CMS by TryGhost
CVE-2026-70594

6.7MEDIUM

Key Information:

Vendor

Tryghost

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-70594?

Ghost CMS, a Node.js content management system, contains a vulnerability where the Ghost Admin did not invalidate user sessions upon login. This flaw could allow attackers to exploit session fixation techniques, leading to unauthorized access. Successful exploitation would require another existing vulnerability on the same domain where Ghost Admin is hosted. This issue has been resolved in version 6.54.1.

Affected Version(s)

Ghost >= 2.2.0, < 6.54.1

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.