If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known.
Metrics
Affected Vendors & Products
References
History
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LDAP Filter Injection in Open‑Xchange OX Dovecot Pro | dovecot: Dovecot: Authentication bypass and information disclosure via LDAP filter injection |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 27 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LDAP Filter Injection in Open‑Xchange OX Dovecot Pro |
Fri, 27 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known. | |
| Weaknesses | CWE-90 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-03-27T12:33:57.043Z
Reserved: 2026-02-24T08:46:09.374Z
Link: CVE-2026-27860
Updated: 2026-03-27T12:33:42.647Z
Status : Received
Published: 2026-03-27T09:16:20.383
Modified: 2026-03-27T09:16:20.383
Link: CVE-2026-27860