EIP-2026-102522

PRE-CVE

Openfire 3.6.4 - Multiple Cross-Site Request Forgery Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102522. PoCs published by Riyaz Ahemed Walikar.

AI-analyzed exploit summary The exploit demonstrates multiple CSRF vulnerabilities in Openfire 3.6.4's administrative section, allowing attackers to perform actions such as creating users, changing passwords, deleting users, and managing groups by tricking authenticated administrators into visiting malicious URLs.

Description

Openfire 3.6.4 - Multiple Cross-Site Request Forgery Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Riyaz Ahemed Walikar · textwebappsjsp
https://www.exploit-db.com/exploits/15918

The exploit demonstrates multiple CSRF vulnerabilities in Openfire 3.6.4's administrative section, allowing attackers to perform actions such as creating users, changing passwords, deleting users, and managing groups by tricking authenticated administrators into visiting malicious URLs.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Openfire 3.6.4
Auth required
Prerequisites: Authenticated administrator session · Victim interaction (e.g., clicking a malicious link)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026