Junglewise Threat Intelligence

CVE-2026-40020: Open-Xchange Dovecot improper access control in IMAP SETACL

CVE-2026-40020 · Severity: low · CVSS 3.1 · Published 2026-05-12

Technologies: Open-Xchange Dovecot CE, Dovecot, Open-Xchange Dovecot Pro. Vendors: Open-Xchange, Dovecot.

Executive brief

Dovecot is a popular open-source email server used to handle incoming mail. A vulnerability allows an authenticated user to bypass security settings and share folders with all other users on the system. While this does not grant unauthorized access to private emails, it can be used to clutter or 'spam' the folder lists of every user on the server.

Technical details

A vulnerability in Dovecot's IMAP SETACL command handling allows an authenticated user to inject 'anyone' permissions into a user's dovecot-acl file. This occurs even when the configuration 'imap_acl_allow_anyone' is explicitly set to 'no'. The root cause is improper access control (CWE-284) during the processing of ACL modification commands. An attacker with valid login credentials can exploit this to make specific folders visible to all users on the system. The impact is limited to folder 'spamming' and does not result in unauthorized data disclosure or privilege escalation.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0, 3.0.5, 3.1.0, 3.1.4, 3.1.5
  • Open-Xchange Dovecot CE 2.4.0, 2.4.3, 2.4.4

Timeline

  • 2026-05-12: advisory: Initial public release of the advisory
  • 2026-05-12: disclosed: CVE-2026-40020 published to NVD

References

Related threats