Executive brief
MoguBlog is a blog platform that uses Elasticsearch for search functionality. Versions through 6.2 expose critical search index management endpoints without requiring authentication, allowing attackers to remotely delete, corrupt, or modify the entire search index. This disrupts blog search capabilities and can be weaponized to inject malicious content into search results.
Technical details
The vulnerability is an authentication bypass in the mogu_search microservice that exposes Elasticsearch index management endpoints (POST /search/initElasticSearchIndex and related endpoints) without requiring credentials. The root cause is overly permissive security configuration in WebSecurityConfig.java that applies permitAll() to /search/** routes before the generic authenticated() check is evaluated. Remote attackers can invoke POST endpoints to delete the entire ES index, recreate it, modify mappings, inject malicious documents, or delete specific entries, resulting in degraded or poisoned search functionality. The vulnerability requires network access to the mogu_search service (typically http://127.0.0.1:8604) but no authentication or user interaction. No patch availability is documented in the advisory.
Affected products
- MoguBlog MoguBlog through 6.2
Timeline
- 2026-09-11: disclosed