Security Advisory

CVE-2026-89264

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-11 15:25:18
Last updated 2026-09-11 16:13:18
Assigner VulnCheck
CVSS score 5.3
State PUBLISHED

Description

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.