Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33606

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in Dovecot. A malicious user can craft specific mail content that, when an administrator later uses the dsync tool with the stream protocol, is interpreted as dsync commands. This command injection allows the user to modify the state of mailboxes on the destination, including internal attributes that should not be directly accessible. This could lead to unauthorized data manipulation and potentially cause service disruptions.

Меры по смягчению последствий

To mitigate this issue, administrators should avoid using the dsync utility with the stream protocol when processing mailboxes that contain untrusted user-provided content. This operational control prevents the crafted mail content from being interpreted as dsync commands during migration or replication tasks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2525574dovecot: Dovecot: Unauthorized mailbox modification via dsync command injection

EPSS

Процентиль: 10%
0.00204
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
17 дней назад

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 4.8
nvd
17 дней назад

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 4.8
debian
17 дней назад

Mail content stored by a user can be crafted so that it is interpreted ...

CVSS3: 4.8
github
17 дней назад

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
12 дней назад

Security update for dovecot22

EPSS

Процентиль: 10%
0.00204
Низкий

5.4 Medium

CVSS3