Description
MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Comment author spoofing (identity impersonation)
Action: Apply patch
AI Analysis

Impact

The vulnerability stems from MoguBlog’s comment posting endpoint failing to validate that the userUid supplied in the request body matches the authenticated user. As a result, any logged‑in user can submit a comment with an arbitrary userUid, causing the comment to appear as though it was authored by another account, including administrators. This flaw is an instance of improper authorization and is classified as CWE‑639.

Affected Systems

MoguBlog versions 6.2 and earlier are affected. The flaw exists in the CommentRestApi handling within the mogu_web module, specifically the POST /web/comment/add endpoint. Any installation running these releases can be exploited if the user is authenticated.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate overall risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Exploitation requires an authenticated session; unauthenticated users cannot provide a valid session token. The attacker can construct a POST payload and set any userUid value, resulting in impersonated comments that may be used to defame or misrepresent an account. The impact is limited to reputational damage and unauthorized content attribution rather than privilege escalation or system compromise.

Generated by OpenCVE AI on September 11, 2026 at 17:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MoguBlog to the latest release that includes the author‑identity validation fix.
  • Modify the server‑side logic so that the userUid field in POST /web/comment/add requests is overwritten with the authenticated user’s ID or rejected if it does not match.
  • If an immediate upgrade is not feasible, implement additional controls such as logging all attempted userUid values for audit and restricting comment posting to users with explicit comment permissions.

Generated by OpenCVE AI on September 11, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Moxi624
Moxi624 mogu Blog V2
Vendors & Products Moxi624
Moxi624 mogu Blog V2

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators.
Title MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity
First Time appeared Mogublog Project
Mogublog Project mogublog
Weaknesses CWE-639
CPEs cpe:2.3:a:mogublog_project:mogublog:*:*:*:*:*:*:*:*
Vendors & Products Mogublog Project
Mogublog Project mogublog
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mogublog Project Mogublog
Moxi624 Mogu Blog V2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:40.414Z

Reserved: 2026-09-11T10:52:56.668Z

Link: CVE-2026-89264

cve-icon Vulnrichment

Updated: 2026-09-11T16:13:06.509Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T16:17:51.193

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-89264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:55:48Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key