Description
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
Published: 2026-10-02
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: User Impersonation / Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability in ProcessOne's ejabberd XMPP server allows an attacker to impersonate arbitrary users by sending a crafted SASL-PLAIN authentication request with an unvalidated authzid value. Because the server accepts this value without verifying it matches the authenticated identity, the attacker can assume the role of any target user, potentially gaining access to private chats, resources, and administrative functions. This flaw results in a complete bypass of user authorization controls.

Affected Systems

The affected product is ProcessOne's ejabberd XMPP server, versions up to and including 26.04. Any deployment running these versions is vulnerable. The issue was addressed in the 26.07 release, which contains the necessary fix, so only versions older than that remain impacted.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity with significant impact on confidentiality, integrity, and availability. No EPSS score is available, and the vulnerability is not listed in CISA KEV, so immediate exploitation risk cannot be quantified, but the nature of the flaw permits credentialed or unauthorized remote users to bypass authentication. The attack vector is inferred to be remote over the network, using the SASL-PLAIN authentication mechanism. A security professional should treat this as a high‑risk authorization bypass until patched or mitigated.

Generated by OpenCVE AI on October 2, 2026 at 13:28 UTC.

Remediation

Vendor Solution

Update to the latest version of ejabberd (26.07)


Vendor Workaround

Disable the SALS-PLAIN authentication mechanism


OpenCVE Recommended Actions

  • Upgrade ejabberd to version 26.07 or later.
  • Disable the SASL-PLAIN authentication mechanism if a patch is not yet applied.
  • If disabling is not possible, restrict network access to the XMPP service and monitor for anomalous authentication attempts.

Generated by OpenCVE AI on October 2, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 02 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
Title User Impersonation/Authorization Bypass in XMPP Server ejabberd
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-10-02T12:19:10.635Z

Reserved: 2026-10-02T11:49:34.103Z

Link: CVE-2026-104733

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T13:17:45.010

Modified: 2026-10-02T13:17:45.010

Link: CVE-2026-104733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:06Z

Weaknesses