CVE-2026-107792
Received Received - Intake

Jivejdon Missing Authorization in Thread Relocation

Vulnerability report for CVE-2026-107792, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
banq jivejdon d58a36b03676e70044b8fab5cb66d21eb83a023d

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Jivejdon allows authenticated users to move threads created by other users without proper authorization. By sending crafted threadId and forumId values to a specific endpoint, attackers can relocate any thread that has no replies to an arbitrary forum.

Impact Analysis

An attacker could disrupt forum organization by moving your threads to unrelated or inappropriate forums. This could lead to confusion, loss of context, or reputational damage if sensitive discussions are misplaced. The impact is limited to threads without replies.

Mitigation Strategies

Update Jivejdon to a version beyond commit ee67a65e to address the missing authorization flaw in UpdateThreadToForumAction.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107792. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart