Junglewise Threat Intelligence

CVE-2026-33606: Open-Xchange Dovecot dsync protocol injection via mail content

CVE-2026-33606 · Severity: medium · CVSS 4.8 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

OX Dovecot Pro is a mail server software used to store and manage email. A vulnerability allows attackers to craft malicious email content that gets interpreted as dsync protocol commands when an administrator runs mail migrations or replication. This can modify mailbox settings, inject unauthorized attributes, or cause migration failures—potentially compromising data integrity during email system upgrades or synchronization.

Technical details

The vulnerability is a protocol injection flaw in OX Dovecot Pro's dsync stream protocol handler. An unprivileged user can craft mail content containing specially formatted data that, when an administrator later runs dsync with the stream protocol (commonly during mailbox migration or replication), is parsed as dsync commands rather than data. This allows an attacker to modify internal mailbox state and attributes on the destination system that users should not be able to set directly. The attack requires the administrator to explicitly run dsync; no publicly available exploits are currently known. Patches are available in versions 2.3.22.2, 3.0.7, and 3.1.6 and later.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5

Timeline

  • 2026-08-28: disclosed: Public advisory released by Open-Xchange
  • 2026-08-28: patched: Fixed in versions 2.3.22.2, 3.0.7, 3.1.6 and later

References

Related threats