CVE-2023-26269: Apache James
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.
Affected products
- Apache James: before 3.7.4 (fixed in 3.7.4)
Published 2023-04-03. Last modified 2026-06-17.