Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40204

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

None None None No publicly available exploits are known.

A flaw was found in Dovecot. This vulnerability allows an attacker to bypass Access Control List (ACL) restrictions through the lda_mailbox_autocreate feature. This could potentially grant unauthorized access to mailboxes or other restricted resources.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2525586dovecot: dovecot: lda_mailbox_autocreate can bypass acl restrictions

EPSS

Процентиль: 8%
0.00179
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
16 дней назад

None None None No publicly available exploits are known.

CVSS3: 3.1
nvd
16 дней назад

None None None No publicly available exploits are known.

CVSS3: 3.1
debian
16 дней назад

None None None No publicly available exploits are known.

CVSS3: 3.1
github
16 дней назад

None None None No publicly available exploits are known.

suse-cvrf
12 дней назад

Security update for dovecot24

EPSS

Процентиль: 8%
0.00179
Низкий

3.1 Low

CVSS3