MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. | |
| Title | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity | |
| First Time appeared |
Mogublog Project
Mogublog Project mogublog |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:mogublog_project:mogublog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mogublog Project
Mogublog Project mogublog |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T16:13:18.525Z
Reserved: 2026-09-11T10:52:56.668Z
Link: CVE-2026-89264
No data.
Status : Received
Published: 2026-09-11T16:17:51.193
Modified: 2026-09-11T16:17:51.193
Link: CVE-2026-89264
No data.
OpenCVE Enrichment
No data.
Weaknesses