CVE-2026-22594
Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22594.json, https://github.com/TryGhost/Ghost/commit/b59f707f670e6f175b669977724ccf16c718430b, https://github.com/TryGhost/Ghost/commit/fc7bc2fb0888513498154ec5cb4b21eccb88de07, https://github.com/TryGhost/Ghost/security/advisories/GHSA-5fp7-g646-ccf4, https://nvd.nist.gov/vuln/detail/CVE-2026-22594
