Authorization Bypass Vulnerability in Jivejdon Product by Banq
CVE-2026-107793
5.3MEDIUM
What is CVE-2026-107793?
Jivejdon, a product by Banq, has a vulnerability that allows an authenticated user to improperly delete subscriptions belonging to other users. Specifically, this flaw resides in the SubscriptionServiceImp.deleteSubscription method, where attackers can exploit this weakness by submitting a delete action to /account/protected/sub/subSaveAction with another user's subscription ID. This functionality enables unauthorized removal of thread, forum, tag, or account subscriptions, presenting a significant risk to user privacy and data integrity.
Affected Version(s)
jivejdon 0 <= 5.0
