CVE-2026-107829
Last modified
CVE-2026-107829 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| banq | jivejdon | <= 5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107829?
How severe is CVE-2026-107829?
How do I fix CVE-2026-107829?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107811Nginx UI is a web user interface for the Nginx web server. F…8.8
- CVE-2026-107812Nginx UI is a web user interface for the Nginx web server. F…7.5
- CVE-2026-107813Nginx UI is a web user interface for the Nginx web server. F…8.8
- CVE-2026-107814MariaDB server is a community developed fork of MySQL server…8.4
- CVE-2026-10782The RealHomes Memberships plugin for WordPress is vulnerable…4.3
- CVE-2026-107828Jivejdon through 5.0 contains an authentication bypass vulne…6.5
- CVE-2026-10783A security flaw has been discovered in gradio-app gradio 6.1…2.5
- CVE-2026-107830Jivejdon from commit e0306088 through commit ee67a65e lacks …5.3
- CVE-2026-107831Jivejdon through 5.0 contains a cross-site request forgery v…4.3
- CVE-2026-10786Improper access control in the ticketing integration setting…6.5
- CVE-2026-10787Missing authorization in the deleted user groups API in Devo…4.3
- CVE-2026-107885OpenPrinting CUPS through 2.4.20 contains a resource-exhaust…3.3
Are you affected by CVE-2026-107829?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
