16 August 2026
Reference: CVE-2026-22594
1. What is being reported?
Ghost, a system used to manage website content, has a problem in its two-factor authentication (2FA) system. Specifically, staff users can skip the email verification step that is supposed to add extra security when logging in. This issue affects versions 5.105.0 to 5.130.5 and 6.0.0 to 6.10.3 of Ghost. The company has released updates that fix this problem.
2. What this means in plain English
If your organisation uses Ghost to run your website, this vulnerability means someone with staff access could log in without completing the usual security check. This could allow unauthorised access to your website’s management area, potentially leading to changes or misuse of your site.
3. Could this affect a small business?
Small businesses or charities using the affected versions of Ghost CMS could be at risk. If you do not use Ghost, or use a different version, this vulnerability likely does not affect you. Check your website software to be sure.
4. What to do now
- Check which version of Ghost your website is running.
- If your version is between 5.105.0 and 5.130.5 or between 6.0.0 and 6.10.3, arrange to update it to version 5.130.6 or 6.11.0 or later.
- If you are unsure how to check or update Ghost, ask your IT provider or website manager for help.
- Review your website user accounts and permissions to ensure only trusted staff have access.
5. Ask your IT provider
Can you confirm if our website uses Ghost CMS, and if so, is it updated to a version that fixes the 2FA bypass vulnerability CVE-2026-22594?
6. Bottom line
Update Ghost CMS promptly if you use it to protect your website from unauthorised access.
Information based on NVD, CISA KEV, and reputable security reporting.