PT-2026-89900 · Moxi624 · Mogu Blog

·

CVE-2026-89261

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-89261

Produtos afetados

Mogu Blog