MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve restricted image-category records including metadata such as name, cover file uid, sort order and timestamps. | |
| Title | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint | |
| First Time appeared |
Mogublog Project
Mogublog Project mogublog |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:mogublog_project:mogublog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mogublog Project
Mogublog Project mogublog |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T20:29:28.878Z
Reserved: 2026-09-11T10:52:56.668Z
Link: CVE-2026-89265
No data.
Status : Deferred
Published: 2026-09-11T16:17:51.337
Modified: 2026-09-11T17:35:21.440
Link: CVE-2026-89265
No data.
OpenCVE Enrichment
Updated: 2026-09-11T16:45:14Z
Weaknesses