Medium severity6.5NVD Advisory· Published Oct 8, 2026
CVE-2026-107828
CVE-2026-107828
Description
Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/api/impl/account/OAuthAccountServiceImp.javanvd
- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/account/oauth/SinaUserCallBackAction.javanvd
- github.com/banq/jivejdon/issues/28nvd
- www.vulncheck.com/advisories/jivejdon-through-5.0-predictable-passwords-via-sina-weibo-oauth-loginnvd
News mentions
0No linked articles in our index yet.