Insufficient Session Expiration in Ghost - CVE-2026-70594

 

Insufficient Session Expiration in Ghost - CVE-2026-70594

Published: July 30, 2026


Vulnerability identifier: #VU140545
CSH Severity: Medium
CVSS v4: 7.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70594
CWE-ID: CWE-613
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to hijack an authenticated session.

The vulnerability exists due to improper session expiration in Ghost Admin when handling login requests. A remote attacker can reuse a fixed session identifier to hijack an authenticated session.

Successful exploitation requires another vulnerability on the same domain where Ghost Admin is hosted, and user interaction is required.


Affected software

Ghost

How to mitigate CVE-2026-70594

Install security update from vendor's website.

Ghost - update to 6.54.1

External References

Related Security Bulletins