CVE-2026-89261Medium· 6.5▾ TwilightPoC availableMoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Exploit / PoC code exists
0.5%
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.
MoguBlog <= 6.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89263Medium· 5.3MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users
CVE-2026-89260High· 7.5MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint
CVE-2026-89265Medium· 4.3MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint
CVE-2026-89262High· 7.5MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check
CVE-2026-89264Medium· 4.3MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user
CVE-2025-13816Medium· 6.3A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2