Home

Description

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

PUBLISHED Reserved 2026-01-20 | Published 2026-03-27 | Updated 2026-03-27 | Assigner OX




HIGH: 7.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Problem types

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version
affected

Any version
affected

References

documentation.open-xchange.com/...26/oxdc-adv-2026-0001.json vendor-advisory

cve.org (CVE-2026-24031)

nvd.nist.gov (CVE-2026-24031)

Download JSON