Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89261— MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

Quick assessment

Affected
moxi624 MoguBlog
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述的中文翻译: MoguBlog 6.2 版本及更早版本中,mogu_search 服务中的 Elasticsearch 索引管理端点未做身份验证,暴露给了外部。远程攻击者可以利用这一点,对博客搜索索引执行删除、重建或修改操作。攻击者可以调用 POST 端点来清空整个搜索索引、删除特定文档,或注入恶意的索引条目,从而导致搜索功能返回错误结果或无结果。 --- 翻译说明与优化建议: 1. 专业术语处理: "exposes ... without authentication" 译为“暴露...且未做身

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89261

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
moxi624 MoguBlog 0 ~ 6.2 -

II. Public POCs for CVE-2026-89261

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89261

登录查看更多情报信息。

Vendor Advisories for CVE-2026-89261 (1)

Proof of Concept for CVE-2026-89261 (4)

Other References for CVE-2026-89261 (2)

Same Patch Batch · moxi624 · 2026-09-11 · 6 CVEs total

CVE-2026-89262 7.5 HIGH MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check
CVE-2026-89260 7.5 HIGH MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback
CVE-2026-89263 5.3 MEDIUM MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint
CVE-2026-89264 4.3 MEDIUM MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity
CVE-2026-89265 4.3 MEDIUM MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

IV. Related Vulnerabilities

V. Comments for CVE-2026-89261

No comments yet


Leave a comment