Back

MEDIUM

MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

Published Sep 11, 2026

Description

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious index entries, causing search functionality to return incorrect or no results.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 11, 2026
Updated Sep 24, 2026
Reserved Sep 11, 2026
CISA Vulnrichment
Updated Sep 11, 2026
NVD
Status Deferred
Modified Sep 11, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Sep 11, 2026
Updated Sep 24, 2026
Exploited since n/a
EUVD-2026-76134