CVE-2026-89261

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 16:17

Updated : 2026-09-11 20:19


NVD link : CVE-2026-89261

Mitre link : CVE-2026-89261

CVE.ORG link : CVE-2026-89261


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function