CVE-2026-107793: Jivejdon through 5.0 IDOR via subSaveAction Subscription Delete
Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated with a low-privileged account. No user interaction is required, and the vulnerable endpoint is reachable over the network.
What access or information does an attacker need?
The attacker needs another user's subscriptionId and can submit it in a delete action to /account/protected/sub/subSaveAction. The affected operation can remove thread, forum, tag, or account subscriptions belonging to the other user.
Which versions are affected?
Jivejdon through version 5.0 is affected.