CVE-2026-104733
Received
Received - Intake
User Impersonation Flaw in ProcessOnes ejabberd Server
Vulnerability report for CVE-2026-104733, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-02
Last updated on: 2026-10-02
Assigner: Switzerland Government Common Vulnerability Program
Description
Description
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| processone | ejabberd | to 26.04 (inc) |
| processone | ejabberd | 26.09 |
| processone | ejabberd | 26.07 |
| processone | ejabberd | 25.10 |
| processone | ejabberd | 16.12 |
| processone | ejabberd | From 25.10 (inc) to 26.07 (exc) |
| processone | ejabberd | From 16.12 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |