Authorization Bypass in MoguBlog Affects Role-Based Permissions
CVE-2026-89265
Key Information:
Badges
What is CVE-2026-89265?
MoguBlog versions up to 6.2 are vulnerable to an authorization bypass via the POST /pictureSort/getPictureSortByUid endpoint. This vulnerability arises from the omission of the @AuthorityVerify annotation necessary for enforcing role-based permissions. As a result, authenticated back-office users without the appropriate image-category permissions can access restricted image-category records. This includes sensitive metadata like category names, cover file identifiers, sort order, and timestamps, which could lead to unauthorized exposure of this information.
Affected Version(s)
MoguBlog 0 <= 6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
