Executive brief
OX Dovecot is an email server component that handles mail access and authentication for enterprise messaging systems. A critical authentication vulnerability allows attackers to bypass login controls and gain unauthorized access to user mailboxes and email data without valid credentials.
Technical details
This vulnerability is a critical authentication bypass in OX Dovecot Pro. The root cause and specific attack vector are not detailed in the available advisory excerpt, but the CVSS score of 7.4 and "critical" aggregate severity indicate a high-impact flaw affecting core authentication mechanisms. Affected versions include 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, and 3.1.0 through 3.1.5. The flaw is network-accessible and requires no user interaction. Patches are available: upgrade to 2.3.22.2, 3.0.7, or 3.1.6.
Affected products
- Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Updates available: 2.3.22.2, 3.0.7, 3.1.6