CVE-2026-104733
HIGH
7,4
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
https://github.com/processone/ejabberd/releases#release-26.07
https://www.nsideattacklogic.de/advisories/NSIDE-SA-2026-004/