CVE-2026-89264

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 16:17

Updated : 2026-09-11 17:35


NVD link : CVE-2026-89264

Mitre link : CVE-2026-89264

CVE.ORG link : CVE-2026-89264


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key