If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known.
References
| Link | Resource |
|---|---|
| https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Apr 2026, 19:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Open-xchange
Open-xchange dovecot Dovecot Dovecot dovecot |
|
| CPE | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
|
| References | () https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.jsonĀ - Vendor Advisory |
27 Mar 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-27 09:16
Updated : 2026-04-29 19:26
NVD link : CVE-2026-27860
Mitre link : CVE-2026-27860
CVE.ORG link : CVE-2026-27860
JSON object : View
Products Affected
dovecot
- dovecot
open-xchange
- dovecot
CWE
CWE-90
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
