CVE-2023-26269: Apache James

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

Affected products

  • Apache James: before 3.7.4 (fixed in 3.7.4)

Published 2023-04-03. Last modified 2026-06-17.