Junglewise Threat Intelligence

CVE-2026-40018: Open-Xchange Dovecot authentication bypass

CVE-2026-40018 · Severity: high · CVSS 7.4 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

OX Dovecot is an email server component that handles mail access and authentication for enterprise messaging systems. A critical authentication vulnerability allows attackers to bypass login controls and gain unauthorized access to user mailboxes and email data without valid credentials.

Technical details

This vulnerability is a critical authentication bypass in OX Dovecot Pro. The root cause and specific attack vector are not detailed in the available advisory excerpt, but the CVSS score of 7.4 and "critical" aggregate severity indicate a high-impact flaw affecting core authentication mechanisms. Affected versions include 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, and 3.1.0 through 3.1.5. The flaw is network-accessible and requires no user interaction. Patches are available: upgrade to 2.3.22.2, 3.0.7, or 3.1.6.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Updates available: 2.3.22.2, 3.0.7, 3.1.6

References

Related threats