Beveiligingsadvies

CVE-2026-89262

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-11 15:25:17
Laatst bijgewerkt 2026-09-11 18:17:21
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.