CVE-2026-89265: MOXI624 Mogublog
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps.
Affected products
- MOXI624 Mogublog: up to and including 6.2
Published 2026-09-11. Last modified 2026-09-11.