CVE-2026-103279
Received Received - Intake

Ghost Session Persistence After Password Change

Vulnerability report for CVE-2026-103279, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ghost ghost From 3.10.0 (inc) to 6.34.0 (exc)
tryghost ghost From 3.10.0 (inc) to 6.34.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Ghost versions from 3.10.0 to 6.34.0. When a user changes their password, Ghost fails to fully invalidate all active sessions. Attackers with a stolen session cookie can maintain access to the user's account even after the password is updated.

Detection Guidance

To detect this vulnerability, check Ghost versions between 3.10.0 and 6.34.0. Use commands like 'ghost version' for CLI or inspect Docker images for version info. Look for active sessions that persist after password changes.

Impact Analysis

If an attacker obtains a valid session cookie, they can retain unauthorized access to your account even after you change your password. This could lead to data theft, unauthorized actions, or prolonged account compromise. The impact is higher for self-hosted instances where session management is critical.

Compliance Impact

This vulnerability could violate compliance requirements that mandate timely session invalidation after password changes, such as GDPR's data protection principles or HIPAA's access controls. Persistent unauthorized access may lead to data breaches, triggering regulatory penalties and reputational damage.

Mitigation Strategies

Immediately update Ghost to version 6.34.0 or later. For self-hosted instances, use Ghost-CLI or Docker to upgrade. Review active sessions and invalidate any suspicious ones after password changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103279. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart