MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 15:30:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T15:25:16.491Z
Reserved: 2026-09-11T10:52:56.668Z
Link: CVE-2026-89261
No data.
Status : Deferred
Published: 2026-09-11T16:17:50.740
Modified: 2026-09-11T17:35:21.440
Link: CVE-2026-89261
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:45:14Z
Weaknesses