Missing Authorization in Ghost - CVE-2026-103268
Published: September 7, 2026 / Updated: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to reactivate a suspended staff account.
The vulnerability exists due to missing authorization in the staff account password-reset functionality when performing a self-service password reset. A remote attacker can reset the password of a suspended staff account to reactivate it.
The impact depends on the original role assigned to the suspended staff account.