Executive brief
OX Dovecot Pro is a mail server software used to store and manage email. A vulnerability allows attackers to craft malicious email content that gets interpreted as dsync protocol commands when an administrator runs mail migrations or replication. This can modify mailbox settings, inject unauthorized attributes, or cause migration failures—potentially compromising data integrity during email system upgrades or synchronization.
Technical details
The vulnerability is a protocol injection flaw in OX Dovecot Pro's dsync stream protocol handler. An unprivileged user can craft mail content containing specially formatted data that, when an administrator later runs dsync with the stream protocol (commonly during mailbox migration or replication), is parsed as dsync commands rather than data. This allows an attacker to modify internal mailbox state and attributes on the destination system that users should not be able to set directly. The attack requires the administrator to explicitly run dsync; no publicly available exploits are currently known. Patches are available in versions 2.3.22.2, 3.0.7, and 3.1.6 and later.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5
Timeline
- 2026-08-28: disclosed: Public advisory released by Open-Xchange
- 2026-08-28: patched: Fixed in versions 2.3.22.2, 3.0.7, 3.1.6 and later