Retour à la veille

CVE-2026-103268

Publié : 1 octobre 2026
Modifié : 1 octobre 2026
Lien officiel NVD
Score CVSS
8.8
HIGH

Description détaillée

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore their original privileges.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Références et Patchs