Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-24031

Опубликовано: 27 мар. 2026
Источник: debian
EPSS Низкий

Описание

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dovecotfixed1:2.4.3+dfsg1-1package
dovecotfixed1:2.4.1+dfsg1-6+deb13u4trixiepackage
dovecotnot-affectedbookwormpackage
dovecotnot-affectedbullseyepackage

Примечания

  • https://dovecot.org/mailman3/archives/list/dovecot-news@dovecot.org/thread/IKIHZX77IPTGSP5WBIPJUOFBUQFKVPE7/

  • https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0001.html#cve-2026-24031-v2-4-v3-1-regression-sql-injection-allows-bypassing-authentication

  • Fixed by: https://github.com/dovecot/core/commit/e2d8ef1ee04662e391e06ae76da1e7216c3a1fd3 (2.4.3)

  • Fixed by: https://github.com/dovecot/core/commit/6a8f2daf15727a36488252efc184dacaa7652cd2 (2.4.3)

  • Fixed by: https://github.com/dovecot/core/commit/34fbd3956db7f0ab1aefccb7750b4ec984681fa8 (2.4.3)

  • Fixed by: https://github.com/dovecot/core/commit/0e1f5abbbb27d7f8a485cd1c6a5673be995025a4 (2.4.3)

  • Fixed by: https://github.com/dovecot/core/commit/74a6f1612e7732026e69e8d8489291842df68589 (2.4.3)

  • Fixed by: https://github.com/dovecot/core/commit/25c34e50848155786d9a00eef6c310502f94e70f (2.4.3)

  • Fixed by: https://github.com/dovecot/core/commit/4049b0a8d5b6ca5c2cbcaadb9b5e81c3cce25044 (2.4.3)

EPSS

Процентиль: 33%
0.00395
Низкий

Связанные уязвимости

CVSS3: 7.7
ubuntu
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
redhat
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
nvd
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
github
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

suse-cvrf
4 месяца назад

Security update for dovecot24

EPSS

Процентиль: 33%
0.00395
Низкий