CVE-2026-89261 PUBLISHED

MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

Assigner: VulnCheck
Reserved: 11.09.2026 Published: 11.09.2026 Updated: 11.09.2026

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor moxi624
Product MoguBlog
Versions Default: unaffected
  • affected from 0 to 6.2 (incl.)

Credits

  • Mingsheng Lin reporter

References

Problem Types

  • Missing Authentication for Critical Function CWE