Authentication Bypass in Jivejdon Affects User Accounts via Weibo Integration
CVE-2026-107828
6.9MEDIUM
What is CVE-2026-107828?
The Jivejdon application, up to version 5.0, has a vulnerability that enables an authentication bypass. This security flaw allows unauthorized attackers to gain access to Weibo-created accounts by leveraging predictable passwords derived from public Weibo user IDs. Specifically, the implementation in OAuthAccountServiceImp assigns the first four digits of the Weibo ID as the password, which can be easily guessed by attackers. This compromise exposes users to unauthorized actions, including reading and posting content as the affected individuals. It is crucial for users and administrators to be aware of this issue and apply necessary mitigations to protect their accounts.
Affected Version(s)
jivejdon 0 <= 5.0
