← Vulnerability feed

Vulnerability record · CVE-2023-32315 · published 26 May 2023

CVE-2023-32315: Openfire admin console path traversal allows unauthenticated access

Igniterealtime · Openfire

Openfire's web-based administrative console is vulnerable to a path traversal flaw reachable through the unauthenticated Setup Environment. On an already-configured server, an unauthenticated attacker can use that setup endpoint to reach Admin Console pages reserved for administrators. It affects Openfire releases from 3.10.0 onward and is patched in 4.7.5 and 4.6.8.

7.5 CVSS 3.1 High CISA KEV since 24 Aug 2023 EPSS 100% · top 0.1% CWE-22 · Path traversal
7.5CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-maximum EPSS score, requires no authentication, and public exploit material is referenced.

What it is

Openfire's web-based administrative console is vulnerable to a path traversal flaw reachable through the unauthenticated Setup Environment. On an already-configured server, an unauthenticated attacker can use that setup endpoint to reach Admin Console pages reserved for administrators. It affects Openfire releases from 3.10.0 onward and is patched in 4.7.5 and 4.6.8.

Impact

An attacker gains access to administrative-only console pages without credentials, exposing sensitive configuration and management functionality. The CVSS vector rates confidentiality impact as high with no integrity or availability impact.

Attack surface

Reachable over the network via HTTP against the Openfire Admin Console setup environment; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The description states the setup environment is used to access restricted admin pages.

Exploitation

Listed in CISA KEV with a due date of 2023-09-14, and EPSS probability is 0.99999 (percentile 0.99992). References are tagged Exploit, including a Packet Storm entry titled Authentication Bypass Remote Code Execution, indicating public exploit material exists.

What to do

  • Upgrade Openfire to 4.7.5 or 4.6.8 (or the 4.8.0 branch when available).
  • If upgrade is not immediately possible, apply the mitigation guidance in vendor advisory GHSA-gw42-f939-fhvm.
  • Restrict network access to the Openfire Admin Console and setup environment to trusted management networks only.
  • Discontinue use of the product if no mitigation is available, per CISA KEV required action.
  • Verify no unauthorized admin accounts or configuration changes were made during any exposure window.

Detection

  • Review Openfire web access logs for requests to setup environment paths containing traversal sequences (e.g., ../) or unexpected admin console URLs from unauthenticated sources.
  • Alert on access to Admin Console pages from IPs outside expected administrative networks.
  • Monitor for creation of new administrative accounts or unexpected configuration changes in Openfire.
  • Correlate Openfire host activity with the public exploit references for post-exploitation behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-32315 to the Known Exploited Vulnerabilities catalog on 24 August 2023 as "Ignite Realtime Openfire Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 14 September 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32315 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-25421Igniterealtime openfire execution with unnecessary privileges vulnerabilityAn issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.EPSS 1.7%9.8CVE-2021-45967Pascom cloud phone system path traversal vulnerabilityAn issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path t…EPSS 21%9.8CVE-2019-18394Igniterealtime openfire server-side request forgery (ssrf) vulnerabilityA Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrar…EPSS 32%7.8CVE-2014-2741Igniterealtime openfire permissions and access controls vulnerabilitynio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of compressed XML elements, which al…EPSS 3.8%7.5CVE-2014-3451Igniterealtime openfire improper certificate validation vulnerabilityOpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.EPSS 1.8%7.5CVE-2008-6508Openfire Admin Console AuthCheck filter path traversal bypasses authenticationThe AuthCheck filter in the Openfire Admin Console fails to properly normalize URIs, allowing a directory traversal sequence to slip past the Exclude…EPSS 84%analysed7.5CVE-2008-6509Igniterealtime openfire sql injection vulnerabilitySQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via …EPSS 2.0%7.2CVE-2024-25420Igniterealtime openfire vulnerabilityAn issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property compon…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-32315), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.