CVE-2026-89262

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 16:17

Updated : 2026-09-11 19:17


NVD link : CVE-2026-89262

Mitre link : CVE-2026-89262

CVE.ORG link : CVE-2026-89262


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key