---
id: CVE-2026-107828
title: >-
  Jivejdon through 5.0 contains an authentication bypass vulnerability that
  allows unauthenticated attackers to access Weibo-created accounts by deriving
  predictable credentials from public Weibo user IDs
summary: >-
  Jivejdon through 5.0 contains an authentication bypass vulnerability that
  allows unauthenticated attackers to access Weibo-created accounts by deriving
  predictable credentials from public Weibo user IDs.
  OAuthAccountServiceImp.transferSi…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-1391
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:30.480'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107828'
references:
  - url: 'https://github.com/banq/jivejdon'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/api/impl/account/OAuthAccountServiceImp.java#L192-L213
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/account/oauth/SinaUserCallBackAction.java#L76-L80
    label: disclosure@vulncheck.com
  - url: 'https://github.com/banq/jivejdon/issues/28'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jivejdon-through-5.0-predictable-passwords-via-sina-weibo-oauth-login
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-08T23:16:47.392Z'
---

## Overview

Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
