CVE-2026-107828mediumCWE-1391

CVE-2026-107828: medium-severity vulnerability in banq jivejdon

Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login

Published

10Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9
exploitation probability
—
observed exploitation
nono source reports it
Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
banq · jivejdon