CVE-2026-107828
Received Received - Intake

Authentication Bypass in Jivejdon via Predictable Weibo Credentials

Vulnerability report for CVE-2026-107828, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
banq jivejdon 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1391 The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in Jivejdon version 5.0 or earlier. It allows unauthenticated attackers to access accounts created via Weibo by predicting passwords. The password is set to the first four digits of a user's Weibo ID, enabling attackers to log in as victims through normal login forms and perform actions like reading or posting content.

Detection Guidance

Check Jivejdon login logs for accounts using passwords derived from Weibo user IDs (first four digits). Inspect OAuthAccountServiceImp.transferSina() for hardcoded password generation logic.

Impact Analysis

If you use Jivejdon with Weibo account integration, attackers could gain unauthorized access to your account. They could read private messages, post content in your name, or perform other actions without your consent. This could lead to reputational damage, data leaks, or misuse of your account.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements. Organizations may face fines, legal liabilities, and reputational harm if they fail to protect user data due to this flaw.

Mitigation Strategies

Update Jivejdon to the latest version. Disable or restrict access to OAuthAccountServiceImp.transferSina(). Implement strong password policies and monitor for unauthorized logins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107828. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart