Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-89264

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Sep 11, 2026
Vendor unknown

Description

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.

References