Authentication Bypass in Jivejdon Affects User Accounts via Weibo Integration
CVE-2026-107828

6.9MEDIUM

Key Information:

Vendor

Banq

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107828?

The Jivejdon application, up to version 5.0, has a vulnerability that enables an authentication bypass. This security flaw allows unauthorized attackers to gain access to Weibo-created accounts by leveraging predictable passwords derived from public Weibo user IDs. Specifically, the implementation in OAuthAccountServiceImp assigns the first four digits of the Weibo ID as the password, which can be easily guessed by attackers. This compromise exposes users to unauthorized actions, including reading and posting content as the affected individuals. It is crucial for users and administrators to be aware of this issue and apply necessary mitigations to protect their accounts.

Affected Version(s)

jivejdon 0 <= 5.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.