Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Security Flaw in Ghost CMS Two-Factor Authentication

A serious security weakness has been found in certain versions of Ghost, a popular website management tool. This flaw lets some users bypass the extra email security step designed to protect accounts. Fixes are available, so updating is important to keep your site safe.

16 August 2026

Reference: CVE-2026-22594

1. What is being reported?

Ghost, a system used to manage website content, has a problem in its two-factor authentication (2FA) system. Specifically, staff users can skip the email verification step that is supposed to add extra security when logging in. This issue affects versions 5.105.0 to 5.130.5 and 6.0.0 to 6.10.3 of Ghost. The company has released updates that fix this problem.

2. What this means in plain English

If your organisation uses Ghost to run your website, this vulnerability means someone with staff access could log in without completing the usual security check. This could allow unauthorised access to your website’s management area, potentially leading to changes or misuse of your site.

3. Could this affect a small business?

Small businesses or charities using the affected versions of Ghost CMS could be at risk. If you do not use Ghost, or use a different version, this vulnerability likely does not affect you. Check your website software to be sure.

4. What to do now

  • Check which version of Ghost your website is running.
  • If your version is between 5.105.0 and 5.130.5 or between 6.0.0 and 6.10.3, arrange to update it to version 5.130.6 or 6.11.0 or later.
  • If you are unsure how to check or update Ghost, ask your IT provider or website manager for help.
  • Review your website user accounts and permissions to ensure only trusted staff have access.

5. Ask your IT provider

Can you confirm if our website uses Ghost CMS, and if so, is it updated to a version that fixes the 2FA bypass vulnerability CVE-2026-22594?

6. Bottom line

Update Ghost CMS promptly if you use it to protect your website from unauthorised access.

Information based on NVD, CISA KEV, and reputable security reporting.

Back to Vulnerability Briefs