Vulnerability Description
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
Related Weaknesses (CWE)
References
- https://github.com/processone/ejabberd/releases#release-26.07
- https://www.nsideattacklogic.de/advisories/NSIDE-SA-2026-004/
FAQ
What is CVE-2026-104733?
CVE-2026-104733 is a documented vulnerability. User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
How severe is CVE-2026-104733?
CVSS scoring is not yet available for CVE-2026-104733. Check NVD for updates.
Is there a patch for CVE-2026-104733?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.