SB20260427163 - Cross-site request forgery in Ghost
Published: April 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site request forgery (CVE-ID: CVE-2026-29784)
The vulnerability allows a remote attacker to take over a Ghost site.
The vulnerability exists due to improper request binding in /session/verify when handling one-time code verification requests. A remote attacker can cause a one-time code to be used in a login session different from the requesting session to take over a Ghost site.
User interaction is required, and exploitation is only possible in some scenarios involving phishing.
Remediation
Install update from vendor's website.