MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply notifications without authorization.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply notifications without authorization. | |
| Title | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint | |
| First Time appeared |
Mogublog Project
Mogublog Project mogublog |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:mogublog_project:mogublog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mogublog Project
Mogublog Project mogublog |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T15:25:17.890Z
Reserved: 2026-09-11T10:52:56.668Z
Link: CVE-2026-89263
No data.
Status : Deferred
Published: 2026-09-11T16:17:51.053
Modified: 2026-09-11T17:35:21.440
Link: CVE-2026-89263
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:45:14Z
Weaknesses