Ghost CMS Vulnerabilities: Privilege Escalation and 2FA Bypass
Article Content
- •Two critical vulnerabilities in Ghost CMS allow privilege escalation and 2FA bypass.
- •Affected versions range from v4.39.0 to v6.64.0 and v6.20.0 to v6.57.1 respectively.
- •Patches are available in the latest releases; users are urged to update immediately.
Two vulnerabilities affecting Ghost CMS have been disclosed. The first, identified as GHSA-v6q3-xqxm-6f5v, allows staff users to discover secret tokens for pending invites, enabling privilege escalation. This affects versions from v4.39.0 to v6.64.0, with a fix in v6.64.0. The second vulnerability, GHSA-q55r-w7fh-rmh6, permits any authenticated staff user to log in as another staff user by bypassing two-factor authentication, impacting versions from v6.20.0 to v6.57.1, with a patch in v6.57.1. Both vulnerabilities were disclosed responsibly by researchers and are for self-hosted instances of Ghost CMS. Users are advised to update their installations promptly to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ghost in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of Ghost are affected?
Have these vulnerabilities been exploited in the wild?
What should I do to protect my Ghost installation?
Continue Reading
Ghost CMS Vulnerabilities: Authentication Bypass and Account Modification Risks Two vulnerabilities have been identified in the Ghost CMS platform affecting versions 5.2.0 to 6.62.0 and 6.20.0 to 6.57.1. The first vulnerability allows unauthenticated account modification during Stripe checkout, while the second enables authentication bypass via session handling. These flaws could potentially…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…