CVE-2026-22594: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-22594 is a two-factor authentication (2FA) bypass vulnerability in Ghost, a Node.js-based content management system. It allows authenticated staff users to skip email-based 2FA verification entirely, gaining unauthorized access to Ghost admin instances. The vulnerability affects Ghost versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, and was disclosed on January 8, 2026, by researcher Sho Odagiri of GMO Cybersecurity by Ierae, Inc. It carries a CVSS v3.1 base score of 8.1 (High) (Ghost Advisory, Github Advisory).

Technical details

The root cause is improper authentication (CWE-287): Ghost's session creation API endpoint (/session) accepted a skipEmailVerification boolean property that was originally intended to reduce friction after a password reset (since a password reset already implies email access). However, because this property was not validated or restricted server-side, any authenticated staff user could manually include skipEmailVerification: true in a POST request to the session creation endpoint to bypass the email 2FA check entirely. The fix removed the skipEmailVerification property and replaced it with a proper TOTP-based OTP flow: after a password reset, the server now generates a short-lived OTP and returns it as emailVerificationToken, which must be submitted as a token parameter in the subsequent session creation request and is cryptographically verified server-side (Ghost Commit, Ghost Advisory).

Impact

Successful exploitation allows a staff-level user with valid credentials to bypass email 2FA and gain a fully authenticated admin session without completing the email verification step. This compromises both confidentiality and integrity of the Ghost CMS instance — an attacker could read sensitive unpublished content, access member/subscriber data, modify site content and configuration, and potentially escalate privileges within the platform. Availability is not directly impacted, but unauthorized administrative access could enable persistent backdoors or content manipulation (Github Advisory, Ghost Advisory).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at the time of disclosure (Github Advisory). The vulnerability requires low privileges (valid staff credentials) and no user interaction, making it straightforward to exploit for any insider or attacker who has obtained staff-level credentials. The EPSS score is approximately 0.008% (1st percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Obtain staff credentials: Acquire valid Ghost staff user credentials through phishing, credential stuffing, or other means targeting a Ghost instance running an affected version (5.105.0–5.130.5 or 6.0.0–6.10.3).
  2. Initiate login: Send a POST request to the Ghost Admin API session endpoint with the staff username and password:
    POST /ghost/api/admin/session
    Content-Type: application/json
    {"username": "staff@example.com", "password": "staffpassword", "skipEmailVerification": true}
  3. Bypass 2FA: By including "skipEmailVerification": true in the request body, the server-side check that would normally require email verification is skipped, and the session is marked as verified without sending or validating any email OTP.
  4. Achieve authenticated access: The server returns a valid authenticated session cookie, granting full staff-level access to the Ghost Admin panel without completing the 2FA email challenge.
  5. Perform unauthorized actions: Use the authenticated session to read sensitive content, modify posts/settings, access member data, or escalate further within the CMS (Ghost Commit, Ghost Advisory).

Indicators of compromise

  • Network: POST requests to /ghost/api/admin/session containing the skipEmailVerification field in the JSON body, originating from unexpected IP addresses or outside normal business hours.
  • Logs: Ghost access logs showing successful admin session creation for staff accounts without a corresponding 2FA email verification event; absence of OTP email delivery records paired with a successful login.
  • Logs: Authentication log entries where a staff user session is established but no email verification code was sent or confirmed in the mail service logs.
  • Process/Behavior: Staff accounts accessing the Ghost Admin panel from new or unrecognized devices/IPs without triggering the expected 2FA email flow.

Mitigation and workarounds

Ghost has released patched versions 5.130.6 (for the 5.x branch) and 6.11.0 (for the 6.x branch) that remove the skipEmailVerification bypass and replace it with a cryptographically verified OTP flow. All Ghost installations running versions 5.105.0–5.130.5 or 6.0.0–6.10.3 should upgrade immediately. No configuration-based workaround is available; upgrading is the only remediation. After patching, administrators should review access logs for suspicious staff login activity during the exposure window (Ghost Advisory, Github Advisory).

Community reactions

The vulnerability was responsibly disclosed by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. and credited in the official Ghost security advisory (Ghost Advisory). The disclosure received coverage from TheHackerWire and was noted on Infosec.exchange and Bluesky CVE tracking accounts shortly after publication. Community reaction was generally measured, noting the low exploitation complexity but also the requirement for prior staff credentials as a limiting factor.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management