CVE-2026-70594
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
- EPSS probability
- 0.16%
- CWE
- CWE-384
- Published
- 2026-08-04
- Last modified
- 2026-08-05
Affected products
- TryGhost Ghost
Weakness type
Related vulnerabilities
- CVE-2026-64857 — tirreno has Session Fixation in Login Authentication
- CVE-2026-86674 — ningzichun Student Management System login.php session_start session fixiation
- CVE-2026-76196 — Photoshop Mobile | Session Fixation (CWE-384)
- CVE-2026-86279 — SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiation
- CVE-2026-85238 — Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking
- CVE-2026-18527 — IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
- CVE-2026-81826 — Flowintel Fails to Invalidate Active Sessions After Password Change
- CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope