CVE-2026-89262: MOXI624 Mogublog

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.

Affected products

  • MOXI624 Mogublog: up to and including 6.2

Published 2026-09-11. Last modified 2026-09-11.