Impact
The vulnerability in ProcessOne's ejabberd XMPP server allows an attacker to impersonate arbitrary users by sending a crafted SASL-PLAIN authentication request with an unvalidated authzid value. Because the server accepts this value without verifying it matches the authenticated identity, the attacker can assume the role of any target user, potentially gaining access to private chats, resources, and administrative functions. This flaw results in a complete bypass of user authorization controls.
Affected Systems
The affected product is ProcessOne's ejabberd XMPP server, versions up to and including 26.04. Any deployment running these versions is vulnerable. The issue was addressed in the 26.07 release, which contains the necessary fix, so only versions older than that remain impacted.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity with significant impact on confidentiality, integrity, and availability. No EPSS score is available, and the vulnerability is not listed in CISA KEV, so immediate exploitation risk cannot be quantified, but the nature of the flaw permits credentialed or unauthorized remote users to bypass authentication. The attack vector is inferred to be remote over the network, using the SASL-PLAIN authentication mechanism. A security professional should treat this as a high‑risk authorization bypass until patched or mitigated.
OpenCVE Enrichment