Security Advisory

CVE-2026-89262

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-11 15:25:17
Last updated 2026-09-11 18:17:21
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.