CVE-2026-89264: MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity

Published Sep 11, 2026
·
Updated

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.

Affected Software

1 affected component
MoguBlog<=6.2

Event History

Sep 11, 2026
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated and able to submit a request to the POST /web/comment/add endpoint. No user interaction from the impersonated account is required.

2

What access or configuration is required for exploitation?

The attacker needs only low-privileged authenticated access and must be able to control the userUid value in the comment request body. The available information does not identify any configuration requirement or mitigation that disables the affected behavior.

3

What is the practical impact?

An authenticated user can create comments that appear to have been authored by another account, including an administrator. The reported impact is integrity loss; no confidentiality or availability impact is specified.

4

How can defenders look for attempted or successful exploitation?

Review comment-creation requests and associated records for userUid values that do not match the authenticated user submitting the request. Comments attributed to privileged or unrelated accounts should be investigated against request logs and session identity data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203