Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-89261

Опубликовано: 11 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

EPSS

Процентиль: 39%
0.00456
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 6.5
github
12 дней назад

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

EPSS

Процентиль: 39%
0.00456
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-306