CVE-2026-107792: Jivejdon through commit ee67a65e Missing Authorization via /message/threadToForum/save Thread Move
Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user can exploit it; no elevated privileges or user interaction are required. The attacker needs to submit crafted threadId and forumId values to the affected endpoint.
What content can be moved?
The issue allows moving other users' threads, but the affected thread must have no replies. A successful request can relocate that thread into an arbitrary forum.
Which versions are affected?
The affected range is Jivejdon from commit d58a36b0 through commit ee67a65e. The provided data does not identify a fixed version or commit.