Medium severity4.3NVD Advisory· Published Sep 11, 2026· Updated Sep 11, 2026
CVE-2026-89264
CVE-2026-89264
Description
MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=6.2
Patches
Vulnerability mechanics
References
4- gitee.com/moxi159753/mogu_blog_v2/releasesnvd
- github.com/LinYuanyi1/cve-request-poc/blob/master/mogublog-poc/C12_comment_add_author_spoof.pynvd
- github.com/moxi624/mogu_blog_v2/blob/025d78c7ac7e19b1abf796fa3cc158d855723d15/mogu_web/src/main/java/com/moxi/mogublog/web/restapi/CommentRestApi.javanvd
- www.vulncheck.com/advisories/mogublog-through-6.2-comment-author-spoofing-via-request-body-identitynvd
News mentions
0No linked articles in our index yet.