CVE-2026-103279: Insufficient Session Expiration in TryGhost Ghost
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
AI Analysis
Technical Summary
CVE-2026-103279 describes an insufficient session expiration vulnerability in the TryGhost Ghost platform. Specifically, versions from 3.10.0 before 6.34.0 fail to fully invalidate all active sessions after a password change. As a result, an attacker who has obtained a stolen session cookie can continue to access the affected user account even after the legitimate user has changed their password, bypassing the intended security control.
Potential Impact
An attacker with a stolen session cookie can maintain unauthorized access to user accounts despite password changes, potentially leading to account compromise and unauthorized actions within the Ghost platform. This undermines the security benefit of password changes as a means to revoke access.
Mitigation Recommendations
A fix is available in Ghost version 6.34.0 and later. Users should upgrade to version 6.34.0 or newer to ensure sessions are properly invalidated after password changes. No additional mitigation guidance is provided in the input data.
CVE-2026-103279: Insufficient Session Expiration in TryGhost Ghost
Description
Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password.
CVSS v4.0
Score 7.6high
Affected software
TryGhost
Ghost
pkg:github/tryghost/GhostRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103279 describes an insufficient session expiration vulnerability in the TryGhost Ghost platform. Specifically, versions from 3.10.0 before 6.34.0 fail to fully invalidate all active sessions after a password change. As a result, an attacker who has obtained a stolen session cookie can continue to access the affected user account even after the legitimate user has changed their password, bypassing the intended security control.
Potential Impact
An attacker with a stolen session cookie can maintain unauthorized access to user accounts despite password changes, potentially leading to account compromise and unauthorized actions within the Ghost platform. This undermines the security benefit of password changes as a means to revoke access.
Mitigation Recommendations
A fix is available in Ghost version 6.34.0 and later. Users should upgrade to version 6.34.0 or newer to ensure sessions are properly invalidated after password changes. No additional mitigation guidance is provided in the input data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-30T10:59:00.638Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abe7495a43b0b3b89bd1d0d
Added to database: 10/01/2026, 14:56:21 UTC
Last enriched: 10/01/2026, 15:23:37 UTC
Last updated: 10/01/2026, 20:49:42 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.