CVE-2026-107793
Received Received - Intake

Authorization Bypass in Jivejdon via Subscription Deletion

Vulnerability report for CVE-2026-107793, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
banq jivejdon 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Jivejdon through version 5.0 has an authorization bypass flaw in the SubscriptionServiceImp.deleteSubscription function. This allows authenticated users to delete other users' subscriptions by providing another user's subscription ID. Attackers can exploit this by sending a delete request to /account/protected/sub/subSaveAction with a different user's subscription ID to remove their thread, forum, tag, or account subscriptions.

Detection Guidance

To detect this vulnerability, monitor HTTP requests to /account/protected/sub/subSaveAction for DELETE operations with a subscriptionId parameter. Check application logs for unauthorized subscription deletions or unusual user activity patterns.

Impact Analysis

If you use Jivejdon, an attacker with access to your account could delete your subscriptions, causing you to lose track of important threads, forums, or tags. This disrupts your workflow and may lead to missed updates or information.

Mitigation Strategies

Implement proper authorization checks in SubscriptionServiceImp.deleteSubscription to ensure users can only delete their own subscriptions. Validate user permissions before processing delete requests to /account/protected/sub/subSaveAction.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107793. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart