CVE-2026-70594
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed in version 6.54.1.
- Affected products
- Ghost
- Fix
- Available
- CVSS 3.1
- 6.7 MEDIUM
- EPSS
- 0.2% (6th percentile)
- Weakness
- CWE-384
- NVD status
- Received
- Published
- 2026-08-04
CVE-2026-70594 at NVD
No indexed exploits for CVE-2026-70594 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-70594 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.