PT-2026-2216 · Ghost · Ghost

Odgrso

·

Publicado

2026-01-08

·

Atualizado

2026-01-15

·

CVE-2026-22594

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ghost versions 5.105.0 through 5.130.5 Ghost versions 6.0.0 through 6.10.3
Description Ghost is a Node.js content management system. A flaw in Ghost’s 2FA mechanism permits staff users to bypass email 2FA. The issue affects the two-factor authentication process for staff users.
Recommendations Ghost version 5.105.0 through 5.130.5 should be updated to version 5.130.6. Ghost version 6.0.0 through 6.10.3 should be updated to version 6.11.0.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-GHOST-2026-22594
CVE-2026-22594
GHSA-5FP7-G646-CCF4

Produtos afetados

Ghost