← Vulnerability feed

Vulnerability record · CVE-2008-6508 · published 23 March 2009

CVE-2008-6508: Openfire Admin Console AuthCheck filter path traversal bypasses authentication

Igniterealtime · Openfire

The AuthCheck filter in the Openfire Admin Console fails to properly normalize URIs, allowing a directory traversal sequence to slip past the Exclude-Strings list. A remote attacker can craft a URI such as /setup/setup-/.. to reach the admin interface without authenticating. This exposes the administrative console of the XMPP server to unauthenticated access.

7.5 CVSS 2.0 High EPSS 84% · top 0.3% CWE-22 · Path traversal
7.5CVSS 2.0 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/.. sequence in a URI.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote access to the administrative interface with public exploit code and very high EPSS probability, though no KEV listing.

What it is

The AuthCheck filter in the Openfire Admin Console fails to properly normalize URIs, allowing a directory traversal sequence to slip past the Exclude-Strings list. A remote attacker can craft a URI such as /setup/setup-/.. to reach the admin interface without authenticating. This exposes the administrative console of the XMPP server to unauthenticated access.

Impact

An attacker gains unauthenticated access to the Openfire admin interface, which can lead to configuration changes, user data exposure, and further compromise of the XMPP server. The CVSS vector indicates partial confidentiality, integrity, and availability impact.

Attack surface

Reachable over the network via HTTP requests to the Openfire Admin Console; no authentication is required and no user interaction is needed. The flaw is triggered by a crafted URI containing a .. sequence that matches the Exclude-Strings list.

Exploitation

Public exploit references are present (OSVDB, SecurityFocus BID, Exploit-DB, and an independent advisory), and EPSS shows a high 30-day probability (0.83382, 99.664th percentile). The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this dataset.

What to do

  • Upgrade Openfire to a version later than 3.6.0a that includes the vendor fix referenced in the changelog and JM-1489.
  • Restrict network access to the Openfire Admin Console (default port 9090) to trusted management hosts only.
  • If the admin console must be exposed, place it behind an authenticating reverse proxy that normalizes paths before forwarding.
  • Review and tighten the AuthCheck Exclude-Strings configuration so that traversal sequences cannot match excluded paths.

Detection

  • Monitor web server and Openfire logs for URIs containing '..' or '/setup/setup-/..' patterns targeting the admin console.
  • Alert on unauthenticated requests to admin console paths that should require authentication.
  • Baseline normal admin console access patterns and flag anomalous source IPs or request sequences.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-6508 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-32315Openfire admin console path traversal allows unauthenticated accessOpenfire's web-based administrative console is vulnerable to a path traversal flaw reachable through the unauthenticated Setup Environment. On an alr…KEVEPSS 100%analysed9.8CVE-2024-25421Igniterealtime openfire execution with unnecessary privileges vulnerabilityAn issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.EPSS 1.7%9.8CVE-2021-45967Pascom cloud phone system path traversal vulnerabilityAn issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path t…EPSS 21%9.8CVE-2019-18394Igniterealtime openfire server-side request forgery (ssrf) vulnerabilityA Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrar…EPSS 32%7.8CVE-2014-2741Igniterealtime openfire permissions and access controls vulnerabilitynio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of compressed XML elements, which al…EPSS 3.8%7.5CVE-2014-3451Igniterealtime openfire improper certificate validation vulnerabilityOpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.EPSS 1.8%7.5CVE-2008-6509Igniterealtime openfire sql injection vulnerabilitySQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via …EPSS 2.0%7.2CVE-2024-25420Igniterealtime openfire vulnerabilityAn issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property compon…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2008-6508), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.