CVE-2026-107793

Source
https://cve.org/CVERecord?id=CVE-2026-107793
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107793.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107793
Published
2026-10-08T21:51:28Z
Modified
2026-10-11T02:46:42Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Jivejdon through 5.0 IDOR via subSaveAction Subscription Delete
Details

Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107793.json"
}
References

Affected packages

Git / github.com/banq/jivejdon

Affected ranges

Type
GIT
Repo
https://github.com/banq/jivejdon
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "5.0"
        },
        {
            "fixed": "5.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107793.json"