Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89264— MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity

Quick assessment

Affected
moxi624 MoguBlog
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MoguBlog 6.2 及以下版本在 POST 端点未能验证评论作者的身份,导致已认证用户可以将评论归属到任意其他用户名下。攻击者可以在请求体中提供任意 值,从而冒充其他账户(包括管理员)发布评论。

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1079
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89264

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity
Source: CVE Program / CVE List V5
Vulnerability Description
MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
moxi624 MoguBlog 0 ~ 6.2 -

II. Public POCs for CVE-2026-89264

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89264

登录查看更多情报信息。

Vendor Advisories for CVE-2026-89264 (1)

Proof of Concept for CVE-2026-89264 (1)

Same Patch Batch · moxi624 · 2026-09-11 · 6 CVEs total

CVE-2026-89262 7.5 HIGH MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check
CVE-2026-89260 7.5 HIGH MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback
CVE-2026-89261 6.5 MEDIUM MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints
CVE-2026-89263 5.3 MEDIUM MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint
CVE-2026-89265 4.3 MEDIUM MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

IV. Related Vulnerabilities

V. Comments for CVE-2026-89264

No comments yet


Leave a comment