CVE-2017-10807: JABBERD2
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
Affected products
- JABBERD2 JABBERD2: up to and including 2.6.0
Published 2017-07-04. Last modified 2026-06-17.