CVE-2026-79323: Magefan/module-blog-graph-ql vulnerability
Published Sep 9, 2026
·Updated
Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql.
Affected Software
1 affected component
magefan/module-blog-graph-ql<=2.2.1
Event History
Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Any remote unauthenticated attacker who can send a POST request to the Magento GraphQL endpoint at /graphql can query the affected blogComments functionality.
2
What information can be exposed?
The issue can disclose blog commenter email addresses as well as internal customer and administrator identifiers.
3
Which installations are affected?
Magefan Blog GraphQL for Magento 2, package magefan/module-blog-graph-ql, is affected through version 2.2.1.