Beveiligingsadvies

CVE-2026-89264

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-11 15:25:18
Laatst bijgewerkt 2026-09-11 16:13:18
Toegewezen door VulnCheck
CVSS-score 5.3
Status PUBLISHED

Beschrijving

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.