Description
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 11 Sep 2026 15:30:00 +0000
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T15:25:16.491Z
Reserved: 2026-09-11T10:52:56.668Z
Link: CVE-2026-89261
No data.
Status : Deferred
Published: 2026-09-11T16:17:50.740
Modified: 2026-09-11T17:35:21.440
Link: CVE-2026-89261
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:45:14Z
Weaknesses