CVE-2026-70594
6.7 MEDIUMpublic exploit availablePublished 2026-08-04 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw allows session fixation attacks due to un invalidated sessions on login in Ghost Admin versions from 2.2.0 to 6.54.1, posing a medium security risk.
- Exploitability
- Exploitation requires another vulnerability on the same domain and is moderately difficult.
- Blast radius
- If exploited, it could lead to unauthorized access or data manipulation within the affected Ghost Admin instance.
- Prioritized remediation
- Upgrade to Ghost version 6.54.1 immediately to mitigate this risk.
session-fixationghost-cmsadmin-panelupgrade
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Weaknesses
CWE-384
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.