CVE-2026-22594: Ghost has Staff 2FA bypass
(updated )
A vulnerability in Ghost’s 2FA mechanism allows staff users to skip email 2FA.
References
- github.com/TryGhost/Ghost
- github.com/TryGhost/Ghost/commit/b59f707f670e6f175b669977724ccf16c718430b
- github.com/TryGhost/Ghost/commit/fc7bc2fb0888513498154ec5cb4b21eccb88de07
- github.com/TryGhost/Ghost/security/advisories/GHSA-5fp7-g646-ccf4
- github.com/advisories/GHSA-5fp7-g646-ccf4
- nvd.nist.gov/vuln/detail/CVE-2026-22594
Code Behaviors & Features
Detect and mitigate CVE-2026-22594 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →