Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40020

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.

A flaw was found in dovecot. A remote attacker can exploit the Internet Message Access Protocol (IMAP) SETACL command to inject "anyone" permissions into a user's dovecot-acl file, even when the imap_acl_allow_anyone setting is disabled. This vulnerability allows an attacker to spam folders to all users, leading to a denial of service by disrupting normal email service. No unauthorized access to user data is gained.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotOut of support scope
Red Hat Enterprise Linux 6dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2476465dovecot: dovecot: Denial of Service via IMAP SETACL command injection

EPSS

Процентиль: 19%
0.00271
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.

CVSS3: 3.1
nvd
3 месяца назад

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.

CVSS3: 3.1
debian
3 месяца назад

Attacker can use the IMAP SETACL command to inject the anyone permissi ...

CVSS3: 3.1
github
3 месяца назад

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.

CVSS3: 4.3
fstec
3 месяца назад

Уязвимость файла dovecot-acl почтовых серверов Dovecot и OX Dovecot Pro, связанная с недостатками разграничения доступа, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00271
Низкий

6.5 Medium

CVSS3