Executive brief
Open-Xchange Dovecot is a widely used email server. A vulnerability in how it processes certain data filters could allow attackers to bypass security protections during the login process. This could lead to unauthorized access to email accounts or the underlying database through injection attacks.
Technical details
A vulnerability exists in Dovecot's variable expansion mechanism where the use of the 'safe' filter incorrectly marks all subsequent pipelines on the same string as safe. This logic error allows unescaped, malicious data to be processed by the application. If these strings are used in authentication queries, an attacker can perform SQL or LDAP injection. The attack requires a specific configuration (use of the safe filter) and has high complexity, but can be executed remotely without prior authentication. Fixes are available in Dovecot Pro 3.1.5 and Dovecot CE 2.4.4.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 through 3.1.4
- Open-Xchange Dovecot CE 2.4.0 through 2.4.3
Timeline
- 2026-03-29: other: Vulnerability discovered
- 2026-05-05: patched: Initial internal release of fix
- 2026-05-12: disclosed: Public advisory released