PT-2026-2216 · Ghost · Ghost
Odgrso
·
Publicado
2026-01-08
·
Atualizado
2026-01-15
·
CVE-2026-22594
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Ghost versions 5.105.0 through 5.130.5
Ghost versions 6.0.0 through 6.10.3
Description
Ghost is a Node.js content management system. A flaw in Ghost’s 2FA mechanism permits staff users to bypass email 2FA. The issue affects the two-factor authentication process for staff users.
Recommendations
Ghost version 5.105.0 through 5.130.5 should be updated to version 5.130.6.
Ghost version 6.0.0 through 6.10.3 should be updated to version 6.11.0.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ghost