An attacker with a valid XMPP account, for example in a chat application, is able to impersonate other users to read and send messages on their behalf. Furthermore, the administrator can be impersonated as well, to call configuration commands for the server, which enables the attacker to add users, reset passwords, stop/restart the server, and more.

Introduction

„ejabberd XMPP Server is a Rock Solid, Massively Scalable, Infinitely Extensible Realtime Platform“ – ProcessOne

Description

The test was conducted against the latest version (26.04) of ejabberd. For the test setup, the container version with the default configuration was used:

Copy to Clipboard

XMPP uses SASL (Simple Authentication and Security Layer) for integrating authentication. SASL supports several different mechanisms, among others: PLAIN. This mechanism is defined in RFC 4616 (https://datatracker.ietf.org/doc/html/rfc4616). The mechanism is simple: it only consists of a single message that is sent from the client to the server. The grammar of that message is specified below:

Copy to Clipboard

However, there is not only a username and a password, but there are actually two identities involved: authcid and authzid. According to the RFC, the authzid is the authorization identity and the authcid is the authentication identity. This is exactly the part that ejabberd implements insecurely. The following paragraph describes how the server should behave:

Upon receipt of the message, the server will verify the presented (in
the message) authentication identity (authcid) and password (passwd)
with the system authentication database, and it will verify that the
authentication credentials permit the client to act as the (presented
or derived) authorization identity (authzid). If both steps succeed,
the user is authenticated.

However, the ejabberd server does not check whether the authentication credential is actually permitted to act as the authorization identity. Due to that issue, it is possible to impersonate arbitrary users, and thus achieve an authorization bypass.

More technical details will be provided in an upcoming blog post.

Risk

A regular chat user is able to impersonate every other chat member on the server. Thus, it is possible to send and receive messages that are intended for other users. Furthermore, it is possible to invoke commands that are restricted to administrative users. Due to critical functions like „Shutdown“, „Restart“, „Change Password“, and other database-related functions, the availability, integrity, and confidentiality of the server can be impacted by an attacker.

Solution/Mitigation

As the vulnerability is only present in the PLAIN authentication mechanism, it is possible to disable this mechanism as a quick workaround:

Copy to Clipboard

Furthermore, it is recommended to update the server to the newest version of ejabberd, where the vulnerability has been fixed.

Disclosure timeline

2026-04-29: Initial contact with vendor to setup a secure channel
2026-05-05: Contacted vendor again
2026-06-12: Contacted vendor again
2026-06-14: Vendor responded, vulnerability information has been exchanged
2026-06-25: Vendor implemented the fix and is in the testing phase.
2026-07-30: Vendor published fixed version
2026-10-01: Advisory published by NSIDE

Contact/Credits

The vulnerability was discovered during an assessment by Marius Schwarz of NSIDE ATTACK LOGIC GmbH.

Disclaimer

The information in this security advisory is provided „as is“ and without warranty of any kind. Details of this security advisory may be updated in order to provide as accurate information as possible. The most recent version of this security advisory can be found at NSIDE ATTACK LOGIC GmbH’s website (https://www.nsideattacklogic.de/).