CVE-2026-104733
Received Received - Intake

User Impersonation Flaw in ProcessOnes ejabberd Server

Vulnerability report for CVE-2026-104733, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Switzerland Government Common Vulnerability Program

Description

User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
processone ejabberd to 26.04 (inc)
processone ejabberd 26.09
processone ejabberd 26.07
processone ejabberd 25.10
processone ejabberd 16.12
processone ejabberd From 25.10 (inc) to 26.07 (exc)
processone ejabberd From 16.12 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104733 is a user impersonation vulnerability in ProcessOne's ejabberd XMPP server versions up to 26.04. It allows an attacker to impersonate any user by exploiting an unvalidated authzid parameter in the SASL-PLAIN authentication mechanism. This means a regular user can send messages or execute commands as another user, including administrative actions.

Detection Guidance

To detect this vulnerability, check if your ejabberd server allows unauthenticated user impersonation via SASL-PLAIN. Monitor logs for unusual authentication attempts or user impersonation events. Verify if PLAIN authentication is enabled by inspecting the server configuration file for disable_sasl_mechanisms settings.

Impact Analysis

This vulnerability enables attackers to impersonate legitimate users, leading to unauthorized access to sensitive data, sending messages on behalf of others, or performing administrative actions like shutting down the server. It compromises confidentiality, integrity, and availability of the XMPP service.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control in GDPR and HIPAA. It allows unauthorized impersonation, which could lead to unauthorized access to personal data, violating confidentiality and integrity principles required by these regulations.

Mitigation Strategies

Immediately disable the PLAIN authentication mechanism by adding disable_sasl_mechanisms: - PLAIN to your ejabberd configuration. This prevents the vulnerability until you can apply a permanent fix. Update ejabberd to the latest version (26.09 or later) to fully resolve the issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104733. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart