3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known.
Basic Information
ID
CVE-2026-27860
Source
OX
Published
Mar 27, 2026 at 08:10
Modified
Mar 27, 2026 at 12:33
Affected Product
Vendor
Open-Xchange GmbH
Product
OX Dovecot Pro
Affected Versions
Open-Xchange GmbH OX Dovecot Pro 0
Open-Xchange GmbH OX Dovecot Pro 0
Open-Xchange GmbH OX Dovecot Pro 0