CVE-2026-22594
published 2026-01-10CVE-2026-22594: Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows…
PriorityP358high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EXPLOIT
EPSS
1.33%
70.2th percentile
Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 5.105.0 < 5.130.6 | 5.130.6 |
| ghost | ghost | >= 5.105.0 < 5.130.6 | 5.130.6 |
| ghost | ghost | >= 6.0.0 < 6.11.0 | 6.11.0 |
| ghost | ghost | >= 6.0.0 < 6.11.0 | 6.11.0 |
| tryghost | ghost | — | — |
| tryghost | ghost | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ghost has Staff 2FA bypass
osv·2026-01-08
CVE-2026-22594 [HIGH] Ghost has Staff 2FA bypass
Ghost has Staff 2FA bypass
### Impact
A vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA.
### Vulnerable versions
This vulnerability is present in Ghost v5.105.0 to v5.130.5 to and Ghost v6.0.0 to v6.10.3.
### Patches
v5.130.6 and v6.11.0 contain a fix for this issue.
### References
Ghost thanks Sho Odagiri of GMO Cybersecurity by Ierae, Inc. for discovering and disclosing this vulnerability responsibly.
### For more information
If there are any questions or comments about this advisory, email Ghost at [[email protected]](mailto:[email protected]).
GHSA
Ghost has Staff 2FA bypass
ghsa·2026-01-08
CVE-2026-22594 [HIGH] CWE-287 Ghost has Staff 2FA bypass
Ghost has Staff 2FA bypass
### Impact
A vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA.
### Vulnerable versions
This vulnerability is present in Ghost v5.105.0 to v5.130.5 to and Ghost v6.0.0 to v6.10.3.
### Patches
v5.130.6 and v6.11.0 contain a fix for this issue.
### References
Ghost thanks Sho Odagiri of GMO Cybersecurity by Ierae, Inc. for discovering and disclosing this vulnerability responsibly.
### For more information
If there are any questions or comments about this advisory, email Ghost at [[email protected]](mailto:[email protected]).
No detection rules found.
Rapid7
Metasploit Wrap Up: Lot of summer shells and fit http profiles
blogs_rapid7·2026-08-14·CVSS 10.0
CVE-2026-46300 [CRITICAL] Metasploit Wrap Up: Lot of summer shells and fit http profiles
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the par
Wiz
CVE-2026-22594 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-22594 [HIGH] CVE-2026-22594 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22594 :
JavaScript vulnerability analysis and mitigation
Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.
Source : NVD
## 8.1
Score
Published January 10, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
JavaScript
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
ghost
Sources
NVD
npm Severity HIGH Has Fix Added at: Jan 11, 2026
Nix Severity HIGH Has Fix Added at: Jan 19, 2026
## Get a CVE
2026-01-10
Published