CVE-2023-32315

HIGHNVD 8.69.0
EchelonGraph scoreHIGH confidence

Score elevated to 9.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2023-08-24), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 8.6 retained for reference. Confidence: HIGH.

Triggered by: CISA KEV (actively exploited)
Sources: cisa_kev, epss, nvd
Trending — 3 sources updated this weekExploited in the wild
8.6
EchelonGraph verdictPatch nowTreat as an emergency — this is being exploited.
  • Actively exploited in the wild (CISA-KEV)
CISA-KEV: ExploitedEPSS: 100%CVSS: 8.6Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.

CVSS v3
8.6
EG Score
9.0(high)
EG Risk
EPSS
100.0%
KEV
⚠ Exploited

Published

May 26, 2023

Last Modified

October 24, 2025

Advisory Details (3)

Auto-updated Jun 2, 2026
⚠️ Active exploitation confirmed. Patch available. Sources: github, cisa.
cisa Patch Available🔴 Active Exploitation

Known Exploited Vulnerabilities Catalog | CISA

Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-32315
github Patch Available

Administration Console authentication bypass · Advisory · igniterealtime/Openfire · GitHub

https://github.com/igniterealtime/Openfire/security/advisories/GHSA-gw42-f939-fhvm

Affected Packages

(1 across 1 ecosystem)
Maven(1)
PackageVulnerable rangeFixed inDependents
org.igniterealtime.openfire:xmppserver4.7.5

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 7× in last 7d / 20× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-22 23:10 UTCEG score recompute
  2. 2026-07-22 19:40 UTCCISA KEV update
  3. 2026-07-21 18:24 UTCEG score recompute
  4. 2026-07-21 15:23 UTCEPSS rescore
  5. 2026-07-21 15:23 UTCEPSS rescore
  6. 2026-07-21 14:37 UTCCISA KEV update
  7. 2026-07-16 17:04 UTCCISA KEV update
  8. 2026-07-15 16:49 UTCCISA KEV update
  9. 2026-07-15 15:04 UTCCISA KEV update
  10. 2026-07-14 18:05 UTCCISA KEV update
  11. 2026-07-13 17:07 UTCCISA KEV update
  12. 2026-07-10 17:52 UTCCISA KEV update
  13. 2026-07-07 19:01 UTCCISA KEV update
  14. 2026-07-07 17:16 UTCCISA KEV update
  15. 2026-07-01 19:16 UTCCISA KEV update
  16. 2026-06-29 19:12 UTCCISA KEV update
  17. 2026-06-25 19:15 UTCCISA KEV update
  18. 2026-06-25 13:48 UTCEPSS rescore
  19. 2026-06-25 13:48 UTCEPSS rescore
  20. 2026-06-23 17:44 UTCCISA KEV update
  21. 2026-06-18 16:13 UTCCISA KEV update
  22. 2026-06-16 19:33 UTCCISA KEV update
  23. 2026-06-15 19:33 UTCCISA KEV update
  24. 2026-06-15 17:47 UTCEPSS rescore
  25. 2026-06-12 17:35 UTCCISA KEV update
Show 17 more
  1. 2026-06-11 19:10 UTCCISA KEV update
  2. 2026-06-09 18:42 UTCCISA KEV update
  3. 2026-06-09 17:12 UTCCISA KEV update
  4. 2026-06-08 19:16 UTCCISA KEV update
  5. 2026-06-08 17:26 UTCCISA KEV update
  6. 2026-06-05 22:43 UTCCISA KEV update
  7. 2026-06-03 19:09 UTCCISA KEV update
  8. 2026-06-02 18:32 UTCCISA KEV update
  9. 2026-06-01 20:42 UTCCISA KEV update
  10. 2026-05-29 22:20 UTCCISA KEV update
  11. 2026-05-27 20:35 UTCCISA KEV update
  12. 2026-05-26 19:13 UTCCISA KEV update
  13. 2026-05-26 07:18 UTCEPSS rescore
  14. 2026-05-26 07:18 UTCEPSS rescore
  15. 2026-05-26 07:18 UTCEPSS rescore
  16. 2026-05-25 00:30 UTCEG score recompute
  17. 2026-05-24 16:52 UTCEPSS rescore

Publicly available exploits

(9 references)

Working exploit code is in the public domain (1 Metasploit module) (7 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.

  • GitHub PoCK3ysTr0K3R/CVE-2023-32315-EXPLOIT
    First seen Dec 15, 2023

    A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass

    Open source ↗
  • GitHub PoCgibran-abdillah/CVE-2023-32315
    First seen Aug 31, 2023

    Tool for CVE-2023-32315 exploitation

    Open source ↗
  • GitHub PoCizzz0/CVE-2023-32315-POC
    First seen Jul 7, 2023

    CVE-2023-32315-Openfire-Bypass

    Open source ↗
  • GitHub PoCAp0dexMe0/CVE-2023-32315
    First seen Jul 2, 2023

    Perform With Massive Openfire Unauthenticated Users

    Open source ↗
  • GitHub PoCmiko550/CVE-2023-32315
    First seen Jun 18, 2023

    Openfire Console Authentication Bypass Vulnerability with RCE plugin

    Open source ↗
  • GitHub PoC5rGJ5aCh5oCq5YW9/CVE-2023-32315exp
    First seen Jun 15, 2023
    Open source ↗
  • GitHub PoCtangxiaofeng7/CVE-2023-32315-Openfire-Bypass
    First seen Jun 14, 2023

    rce

    Open source ↗
  • Metasploitexploit/multi/http/openfire_auth_bypass_rce_cve_2023_32315✓ verified
    First seen May 26, 2023

    Openfire authentication bypass with RCE plugin

    Open source ↗
  • Nucleihttp/cves/2023/CVE-2023-32315.yaml
    First seen Jan 1, 2023

    Openfire Administration Console - Authentication Bypass

    Open source ↗

Frequently asked(6)

What is CVE-2023-32315?
CVE-2023-32315 is a high vulnerability published on May 26, 2023. Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup…
When was CVE-2023-32315 disclosed?
CVE-2023-32315 was first published in the National Vulnerability Database on May 26, 2023, with the most recent update on October 24, 2025. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2023-32315 actively exploited?
Yes. CISA added CVE-2023-32315 to the Known Exploited Vulnerabilities catalog on August 24, 2023, affecting Ignite Realtime Openfire. KEV listing indicates confirmed exploitation in the wild; this CVE warrants immediate patching attention.
What is the CVSS score of CVE-2023-32315?
CVE-2023-32315 has a CVSS v3 base score of 8.6 (NVD). EchelonGraph synthesises NVD + CISA KEV + FIRST EPSS + GHSA into a combined EG score of 9.0.
Which products are affected by CVE-2023-32315?
CVE-2023-32315 affects Ignite Realtime Openfire. The full affected-products list, including version ranges and fixed versions, is shown in the Affected Packages section of this page.
How do I remediate CVE-2023-32315?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2023-32315, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-32315

Explore →

Is Your Infrastructure Affected by CVE-2023-32315?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.