PT-2026-104319 · Jabberd · Ejabberd
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
ejabberd versions prior to 26.05
Description
An issue in the SASL-PLAIN mechanism allows an attacker to impersonate arbitrary users. This occurs due to the lack of validation of the
authzid parameter, which is used to specify the authorization identity during the authentication process.Recommendations
Update to a version newer than 26.04.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ejabberd