๐Ÿ” CVE Alert

CVE-2026-104733

UNKNOWN 0.0

User Impersonation/Authorization Bypass in XMPP Server ejabberd

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.

Vendor processone
Product ejabberd
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for processone ejabberd

Be the first to know when new unknown vulnerabilities affecting processone ejabberd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ProcessOne / ejabberd
0 โ‰ค 26.04

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nsideattacklogic.de: https://www.nsideattacklogic.de/advisories/NSIDE-SA-2026-004/ github.com: https://github.com/processone/ejabberd/releases#release-26.07

Credits

Marius Schwarz (NSIDE ATTACK LOGIC GmbH)