GHSA-fx6f-5qgf-9fmxHighCVSS 7.7
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin....
🔗 CVE IDs covered (1)
📋 Description
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-24031
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
- https://access.redhat.com/security/cve/CVE-2026-24031
- https://bugzilla.redhat.com/show_bug.cgi?id=2452181
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24031.json
- https://github.com/advisories/GHSA-fx6f-5qgf-9fmx