Insufficient Session Expiration in Ghost - CVE-2026-70594
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to hijack an authenticated session.
The vulnerability exists due to improper session expiration in Ghost Admin when handling login requests. A remote attacker can reuse a fixed session identifier to hijack an authenticated session.
Successful exploitation requires another vulnerability on the same domain where Ghost Admin is hosted, and user interaction is required.