CVE-2026-22595

Ghost has Staff Token permission bypass

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have been authenticated via Staff Tokens for Admin/Owner-role users would have had access to these endpoints. This issue has been patched in versions 5.130.6 and 6.11.0.


We have discovered 6,927 live websites that are affected by CVE-2026-22595.

Run a Free Instant Scan




Affected Software

Product  Ghost
Category Headless CMS
Vulnerable Domains6,927 live websites (50% of Ghost install base)
Vulnerable Versions
  • from 5.121 through 5.130.6
  • from 6 through 6.11
Vulnerable Versions Count19 versions ( 6.62% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jan 10, 2026
  • Updated - Jan 12, 2026

Website Distribution by Country

Number of websites using CVE-2026-22595
United States5,211 websites



Germany553 websites
GB228 websites
France169 websites
Singapore80 websites
Canada80 websites
Netherlands55 websites
Russia50 websites
Australia38 websites
Italy33 websites

Website Distribution by TLD

Number of websites using CVE-2026-22595
.com3,753 websites
.org376 websites
.io334 websites
.net289 websites
.de173 websites
.co.uk125 websites
.co98 websites
.fr87 websites
.nl70 websites
.ca58 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-22595

Top websites that are affected by CVE-2026-22595. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States***
**********.com United States***
*.*****************.org United States***
*****.org Singapore*,***
********.com United States*,***
************.com United States*,***
****.************.com United States*,***
****.****.com United States*,***
***************.nl Netherlands**,***
*******.ca Canada**,***
See full domain list

FAQ

CVE-2026-22595 is Incorrect Authorization in Ghost
A total of 6,927 websites have been identified as vulnerable to CVE-2026-22595, based on global website indexing conducted by WebTechSurvey.
The Ghost is affected by the CVE-2026-22595 vulnerability.
Ghost versions up to 6.11 are vulnerable to CVE-2026-22595.
CVE-2026-22595 is resolved in version 6.11 of Ghost.