Junglewise Threat Intelligence

CVE-2026-40204: Open-Xchange Dovecot authentication bypass

CVE-2026-40204 · Severity: low · CVSS 3.1 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

OX Dovecot Pro is an email server component that handles user authentication and message access. A critical authentication bypass vulnerability allows attackers to access email accounts and sensitive messages without valid credentials, potentially exposing confidential business communications and customer data across multiple deployed instances.

Technical details

This is a critical authentication bypass vulnerability in OX Dovecot Pro's authentication mechanism. The vulnerability affects multiple version series (2.3.x, 3.0.x, 3.1.x) and allows unauthenticated network attackers to bypass security controls and gain unauthorized access to user mailboxes. The flaw requires no special privileges or user interaction. Affected versions are 2.3.0 through 2.3.22.1, 3.0.0 through 3.0.6, and 3.1.0 through 3.1.5. Patches are available: update to 2.3.22.2, 3.0.7, or 3.1.6 or later.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0-2.3.22.1, 3.0.0-3.0.6, 3.1.0-3.1.5

Timeline

  • 2026-08-28: disclosed: Public release of security advisory OXDC-ADV-2026-0003
  • 2026-08-28: patched: Patches available in versions 2.3.22.2, 3.0.7, 3.1.6

References

Related threats