CVE-2026-89265

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 16:17

Updated : 2026-09-11 21:17


NVD link : CVE-2026-89265

Mitre link : CVE-2026-89265

CVE.ORG link : CVE-2026-89265


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization