CVE-2026-89262: MOXI624 Mogublog
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.
Affected products
- MOXI624 Mogublog: up to and including 6.2
Published 2026-09-11. Last modified 2026-09-11.