CVE-2026-104733: User Impersonation in ProcessOne ejabberd
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
AI Analysis
Technical Summary
The vulnerability CVE-2026-104733 affects ProcessOne ejabberd XMPP server versions from 0 up to but not including 26.07. It arises from improper validation of the authzid parameter in the SASL-PLAIN authentication mechanism, enabling an attacker with low privileges to impersonate arbitrary users. The CVSS 4.0 base score is 7.4, indicating a high severity with network attack vector, low attack complexity, no user interaction, and high impacts on confidentiality, integrity, and availability. No known exploits in the wild have been reported, and no patch or vendor advisory information is provided in the input data.
Potential Impact
Successful exploitation allows an attacker with limited privileges to impersonate any user on the ejabberd server, potentially gaining unauthorized access to user accounts and sensitive communications. This can compromise confidentiality and integrity of data and disrupt service availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the SASL-PLAIN mechanism or implement additional authentication controls to mitigate risk.
CVE-2026-104733: User Impersonation in ProcessOne ejabberd
Description
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
CVSS v4.0
Score 7.4high
Affected software
ProcessOne
ejabberd
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-104733 affects ProcessOne ejabberd XMPP server versions from 0 up to but not including 26.07. It arises from improper validation of the authzid parameter in the SASL-PLAIN authentication mechanism, enabling an attacker with low privileges to impersonate arbitrary users. The CVSS 4.0 base score is 7.4, indicating a high severity with network attack vector, low attack complexity, no user interaction, and high impacts on confidentiality, integrity, and availability. No known exploits in the wild have been reported, and no patch or vendor advisory information is provided in the input data.
Potential Impact
Successful exploitation allows an attacker with limited privileges to impersonate any user on the ejabberd server, potentially gaining unauthorized access to user accounts and sensitive communications. This can compromise confidentiality and integrity of data and disrupt service availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the SASL-PLAIN mechanism or implement additional authentication controls to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NCSC.ch
- Date Reserved
- 2026-10-02T11:49:34.103Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abfab3aa43b0b3b89bc8b56
Added to database: 10/02/2026, 13:01:46 UTC
Last enriched: 10/02/2026, 13:16:31 UTC
Last updated: 10/03/2026, 04:00:58 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.