CVE-2026-103268
Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.
- Published Oct 1, 2026
- CVSS 8.7 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available