← Back to search

CVE-2026-70594

6.7 MEDIUMpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows session fixation attacks due to un invalidated sessions on login in Ghost Admin versions from 2.2.0 to 6.54.1, posing a medium security risk.
Exploitability
Exploitation requires another vulnerability on the same domain and is moderately difficult.
Blast radius
If exploited, it could lead to unauthorized access or data manipulation within the affected Ghost Admin instance.
Prioritized remediation
Upgrade to Ghost version 6.54.1 immediately to mitigate this risk.
session-fixationghost-cmsadmin-panelupgrade

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

Weaknesses

CWE-384

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.