CVE-2026-70594
published 2026-08-04CVE-2026-70594: Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for…
PriorityP430medium6.7CVSS 3.1
AVAACHPRNUIRSUCHIHAL
EPSS
0.24%
14.2th percentile
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 2.2.0 < 6.54.1 | 6.54.1 |
| tryghost | ghost | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TryGhost up to 6.54.0 Admin session fixiation
vuldb·2026-08-05·CVSS 6.7
CVE-2026-70594 [MEDIUM] TryGhost up to 6.54.0 Admin session fixiation
A vulnerability marked as problematic has been reported in TryGhost Ghost up to 6.54.0. Affected by this issue is some unknown functionality of the component Admin. The manipulation leads to session fixiation.
This vulnerability is documented as CVE-2026-70594. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
Ghost: Session Fixation in Ghost Admin
ghsa·2026-08-04
CVE-2026-70594 [MEDIUM] CWE-384 Ghost: Session Fixation in Ghost Admin
Ghost: Session Fixation in Ghost Admin
### Impact
Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.
### Vulnerable versions
This vulnerability is present in Ghost from v2.2.0 to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to update
For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost).
If your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://docs.ghost.org/update).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-04
Published