CVE-2026-104733 User Impersonation in ProcessOnes XMMP Server… — CVE Notify — TG.ME

🚨 CVE-2026-104733
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.

🎖@cveNotify
GitHub
Releases · processone/ejabberd
Robust, Ubiquitous and Massively Scalable Messaging Platform (XMPP, MQTT, SIP Server) - processone/ejabberd
October 2, 2026 10