
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22594 is a two-factor authentication (2FA) bypass vulnerability in Ghost, a Node.js-based content management system. It allows authenticated staff users to skip email-based 2FA verification entirely, gaining unauthorized access to Ghost admin instances. The vulnerability affects Ghost versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, and was disclosed on January 8, 2026, by researcher Sho Odagiri of GMO Cybersecurity by Ierae, Inc. It carries a CVSS v3.1 base score of 8.1 (High) (Ghost Advisory, Github Advisory).
The root cause is improper authentication (CWE-287): Ghost's session creation API endpoint (/session) accepted a skipEmailVerification boolean property that was originally intended to reduce friction after a password reset (since a password reset already implies email access). However, because this property was not validated or restricted server-side, any authenticated staff user could manually include skipEmailVerification: true in a POST request to the session creation endpoint to bypass the email 2FA check entirely. The fix removed the skipEmailVerification property and replaced it with a proper TOTP-based OTP flow: after a password reset, the server now generates a short-lived OTP and returns it as emailVerificationToken, which must be submitted as a token parameter in the subsequent session creation request and is cryptographically verified server-side (Ghost Commit, Ghost Advisory).
Successful exploitation allows a staff-level user with valid credentials to bypass email 2FA and gain a fully authenticated admin session without completing the email verification step. This compromises both confidentiality and integrity of the Ghost CMS instance — an attacker could read sensitive unpublished content, access member/subscriber data, modify site content and configuration, and potentially escalate privileges within the platform. Availability is not directly impacted, but unauthorized administrative access could enable persistent backdoors or content manipulation (Github Advisory, Ghost Advisory).
No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at the time of disclosure (Github Advisory). The vulnerability requires low privileges (valid staff credentials) and no user interaction, making it straightforward to exploit for any insider or attacker who has obtained staff-level credentials. The EPSS score is approximately 0.008% (1st percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
POST /ghost/api/admin/session
Content-Type: application/json
{"username": "staff@example.com", "password": "staffpassword", "skipEmailVerification": true}"skipEmailVerification": true in the request body, the server-side check that would normally require email verification is skipped, and the session is marked as verified without sending or validating any email OTP./ghost/api/admin/session containing the skipEmailVerification field in the JSON body, originating from unexpected IP addresses or outside normal business hours.Ghost has released patched versions 5.130.6 (for the 5.x branch) and 6.11.0 (for the 6.x branch) that remove the skipEmailVerification bypass and replace it with a cryptographically verified OTP flow. All Ghost installations running versions 5.105.0–5.130.5 or 6.0.0–6.10.3 should upgrade immediately. No configuration-based workaround is available; upgrading is the only remediation. After patching, administrators should review access logs for suspicious staff login activity during the exposure window (Ghost Advisory, Github Advisory).
The vulnerability was responsibly disclosed by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. and credited in the official Ghost security advisory (Ghost Advisory). The disclosure received coverage from TheHackerWire and was noted on Infosec.exchange and Bluesky CVE tracking accounts shortly after publication. Community reaction was generally measured, noting the low exploitation complexity but also the requirement for prior staff credentials as a limiting factor.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."