CVE-2026-24031

HIGH

OX Dovecot Pro <3.1.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

References (1)

Core 1

Scores

CVSS v3 7.7
EPSS 0.0003
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (4)
dovecot/dovecot < 2.4.3
open-xchange/dovecot < 3.1.4
Open-Xchange GmbH/OX Dovecot Pro < 2.4.0
Open-Xchange GmbH/OX Dovecot Pro < 3.1.0
Published Mar 27, 2026
Tracked Since Mar 27, 2026