MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints. | |
| Title | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check | |
| First Time appeared |
Mogublog Project
Mogublog Project mogublog |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:mogublog_project:mogublog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mogublog Project
Mogublog Project mogublog |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T15:25:17.192Z
Reserved: 2026-09-11T10:52:56.668Z
Link: CVE-2026-89262
No data.
Status : Received
Published: 2026-09-11T16:17:50.907
Modified: 2026-09-11T16:17:50.907
Link: CVE-2026-89262
No data.
OpenCVE Enrichment
No data.
Weaknesses