Skip to content
Ghost CMS Vulnerabilities: Privilege Escalation and 2FA Bypass

Ghost CMS Vulnerabilities: Privilege Escalation and 2FA Bypass

First seen 4 Oct 2026, 05:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 08:03 UTC
  • •Two critical vulnerabilities in Ghost CMS allow privilege escalation and 2FA bypass.
  • •Affected versions range from v4.39.0 to v6.64.0 and v6.20.0 to v6.57.1 respectively.
  • •Patches are available in the latest releases; users are urged to update immediately.

Two vulnerabilities affecting Ghost CMS have been disclosed. The first, identified as GHSA-v6q3-xqxm-6f5v, allows staff users to discover secret tokens for pending invites, enabling privilege escalation. This affects versions from v4.39.0 to v6.64.0, with a fix in v6.64.0. The second vulnerability, GHSA-q55r-w7fh-rmh6, permits any authenticated staff user to log in as another staff user by bypassing two-factor authentication, impacting versions from v6.20.0 to v6.57.1, with a patch in v6.57.1. Both vulnerabilities were disclosed responsibly by researchers and are for self-hosted instances of Ghost CMS. Users are advised to update their installations promptly to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
GHSA-q55r-w7fh-rmh6 disclosed
A session handling bug was reported allowing staff users to bypass 2FA and log in as others.
Article 2
2026-10-03
GHSA-v6q3-xqxm-6f5v disclosed
A privilege escalation vulnerability was disclosed, allowing staff users to accept pending invites for higher roles.
Article 1

More articles in this cluster (2)

Following this threat?

Track Ghost in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of Ghost are affected?
Versions from v4.39.0 to v6.64.0 for the privilege escalation issue, and v6.20.0 to v6.57.1 for the 2FA bypass.
Have these vulnerabilities been exploited in the wild?
No confirmed exploitation has been reported; both vulnerabilities have been disclosed and patched.
What should I do to protect my Ghost installation?
Update to the latest versions (v6.64.0 and v6.57.1) to mitigate these vulnerabilities.