Junglewise Threat Intelligence

CVE-2026-89265: MoguBlog authorization bypass in picture sort endpoint

CVE-2026-89265 · Severity: medium · CVSS 4.3 · Published 2026-09-11

Technologies: Mogublog.

Executive brief

MoguBlog is an open-source blogging platform that includes administrative features for managing content such as pictures and categories. An authenticated back-office user without proper image-category permissions can bypass authorization checks to retrieve restricted image metadata (names, file references, sort order, timestamps) by calling a specific API endpoint. This allows low-privilege administrators to access sensitive configuration data they should not be able to view.

Technical details

This vulnerability is a broken function-level authorization (BFLA) / privilege escalation caused by a missing @AuthorityVerify annotation on the POST /pictureSort/getPictureSortByUid endpoint in MoguBlog's PictureSortRestApi controller. All sibling methods in the same controller carry the @AuthorityVerify annotation to enforce role-based access control, but this single endpoint omits it. As a result, the request falls through to the default authentication guard which only checks that a user is logged in, not that they have the required permission. An authenticated back-office user with a valid JWT token can supply a category uid and retrieve restricted image-category records including metadata such as name, cover file uid, sort order, and timestamps. The attack requires valid credentials and network access to the admin endpoint, but no additional user interaction.

Affected products

  • MoguBlog MoguBlog through 6.2

Timeline

  • 2026-09-11: disclosed

References