Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6197-1 | dovecot security update |
Ubuntu USN |
USN-8136-1 | Dovecot vulnerabilities |
Wed, 29 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dovecot
Dovecot dovecot Open-xchange dovecot |
|
| CPEs | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
|
| Vendors & Products |
Dovecot
Dovecot dovecot Open-xchange dovecot |
Mon, 30 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-xchange
Open-xchange ox Dovecot Pro |
|
| Vendors & Products |
Open-xchange
Open-xchange ox Dovecot Pro |
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass via Dovecot SQL Authentication When auth_username_chars Cleared | dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_chars configuration |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 27 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass via Dovecot SQL Authentication When auth_username_chars Cleared |
Fri, 27 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-03-27T19:40:35.437Z
Reserved: 2026-01-20T14:56:25.872Z
Link: CVE-2026-24031
No data.
Status : Analyzed
Published: 2026-03-27T09:16:19.447
Modified: 2026-04-29T19:21:37.743
Link: CVE-2026-24031
OpenCVE Enrichment
Updated: 2026-03-30T07:59:47Z
Debian DSA
Ubuntu USN