CVE-2023-26269
published 2023-04-03CVE-2023-26269: Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.65%
47.2th percentile
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a
malicious local user.
Administrators are advised to disable JMX, or set up a JMX password.
Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ant-media | ant-media-server | — | — |
| apache | james | < 3.7.4 | 3.7.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa7.8HIGH
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ant Media Server vulnerable to a local privilege escalation
ghsa·2024-04-22·CVSS 7.8
CVE-2024-32656 [HIGH] CWE-862 Ant Media Server vulnerable to a local privilege escalation
Ant Media Server vulnerable to a local privilege escalation
### Impact
We have identified a local privilege escalation vulnerability in Ant Media Server which allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability arises from Ant Media Server running with Java Management Extensions (JMX) enabled and authentication disabled on localhost on port 5599/TCP. This vulnerability is nearly identical to the local privilege escalation vulnerability CVE-2023-26269 identified in Apache James.
Any unprivileged operating system user can connect to the JMX service running on port 5599/TCP on localhost and leverage the MLet Bean within JMX to load a remote MBean from an attacker-controlled server. This allows an attacker to
OSV
Ant Media Server vulnerable to a local privilege escalation
osv·2024-04-22·CVSS 7.8
CVE-2024-32656 [HIGH] Ant Media Server vulnerable to a local privilege escalation
Ant Media Server vulnerable to a local privilege escalation
### Impact
We have identified a local privilege escalation vulnerability in Ant Media Server which allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability arises from Ant Media Server running with Java Management Extensions (JMX) enabled and authentication disabled on localhost on port 5599/TCP. This vulnerability is nearly identical to the local privilege escalation vulnerability CVE-2023-26269 identified in Apache James.
Any unprivileged operating system user can connect to the JMX service running on port 5599/TCP on localhost and leverage the MLet Bean within JMX to load a remote MBean from an attacker-controlled server. This allows an attacker to
OSV
Apache James server's JMX management service vulnerable to privilege escalation by local user
osv·2023-04-03
CVE-2023-26269 [HIGH] Apache James server's JMX management service vulnerable to privilege escalation by local user
Apache James server's JMX management service vulnerable to privilege escalation by local user
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.
GHSA
Apache James server's JMX management service vulnerable to privilege escalation by local user
ghsa·2023-04-03
CVE-2023-26269 [HIGH] CWE-862 Apache James server's JMX management service vulnerable to privilege escalation by local user
Apache James server's JMX management service vulnerable to privilege escalation by local user
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-03
Published