Missing Authorization in Jivejdon Allows Thread Manipulation by Authenticated Users
CVE-2026-107792

5.3MEDIUM

Key Information:

Vendor

Banq

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107792?

Jivejdon contains a vulnerability in the UpdateThreadToForumAction process that permits authenticated users to exploit missing authorization. This vulnerability allows attackers to manipulate forum threads by relocating reply-less threads to arbitrary forums through specially crafted parameters in API calls. The affected component can be exploited by sending manipulated threadId and forumId values to the endpoint /message/threadToForum/save, enabling unauthorized movement of thread content. This security oversight emphasizes the importance of implementing stringent authorization checks to prevent misuse.

Affected Version(s)

jivejdon d58a36b03676e70044b8fab5cb66d21eb83a023d

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.