PT-2026-104319 · Jabberd · Ejabberd

·

CVE-2026-104733

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions ejabberd versions prior to 26.05
Description An issue in the SASL-PLAIN mechanism allows an attacker to impersonate arbitrary users. This occurs due to the lack of validation of the authzid parameter, which is used to specify the authorization identity during the authentication process.
Recommendations Update to a version newer than 26.04.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104733

Affected Products

Ejabberd