Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.
PUBLISHED5.2CWE-1391
Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login
Problem type
Affected products
banq
jivejdon
<= 5.0 - AFFECTED
References
GitHub Issue #28
https://github.com/banq/jivejdon/issues/28
github.com
https://github.com/banq/jivejdon
github.com
https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/api/impl/account/OAuthAccountServiceImp.java#L192-L213
github.com
https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/account/oauth/SinaUserCallBackAction.java#L76-L80
VulnCheck Advisory: Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login
https://www.vulncheck.com/advisories/jivejdon-through-5.0-predictable-passwords-via-sina-weibo-oauth-login
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-107828Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-107828",
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"dateUpdated": "2026-10-08T21:51:32.815Z",
"dateReserved": "2026-10-08T21:43:58.211Z",
"datePublished": "2026-10-08T21:51:32.815Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck",
"dateUpdated": "2026-10-08T21:51:32.815Z"
},
"datePublic": "2026-10-08T00:00:00.000Z",
"title": "Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login",
"descriptions": [
{
"lang": "en",
"value": "Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims."
}
],
"affected": [
{
"vendor": "banq",
"product": "jivejdon",
"repo": "https://github.com/banq/jivejdon",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "5.0"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Use of Weak Credentials",
"cweId": "CWE-1391",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/banq/jivejdon/issues/28",
"name": "GitHub Issue #28",
"tags": [
"issue-tracking"
]
},
{
"url": "https://github.com/banq/jivejdon",
"tags": [
"product"
]
},
{
"url": "https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/api/impl/account/OAuthAccountServiceImp.java#L192-L213",
"tags": [
"technical-description"
]
},
{
"url": "https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/account/oauth/SinaUserCallBackAction.java#L76-L80",
"tags": [
"technical-description"
]
},
{
"url": "https://www.vulncheck.com/advisories/jivejdon-through-5.0-predictable-passwords-via-sina-weibo-oauth-login",
"name": "VulnCheck Advisory: Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login",
"tags": [
"third-party-advisory"
]
}
],
"metrics": [
{
"format": "CVSS"
},
{
"format": "CVSS",
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
}
}
],
"credits": [
{
"lang": "en",
"value": "Ikram-4",
"type": "finder"
}
]
}
}
}