Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24031

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 7.7
CVSS3: 8.2
EPSS Низкий

Описание

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
Версия до 2.4.3 (исключая)
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
Версия до 3.1.4 (исключая)

EPSS

Процентиль: 33%
0.00395
Низкий

7.7 High

CVSS3

8.2 High

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 7.7
ubuntu
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
redhat
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

CVSS3: 7.7
debian
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_ch ...

CVSS3: 7.7
github
5 месяцев назад

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

suse-cvrf
4 месяца назад

Security update for dovecot24

EPSS

Процентиль: 33%
0.00395
Низкий

7.7 High

CVSS3

8.2 High

CVSS3

Дефекты

CWE-89
CWE-89