Junglewise Threat Intelligence

CVE-2026-40205: Open-Xchange Dovecot OAuth2 scope validation bypass

CVE-2026-40205 · Severity: medium · CVSS 5.9 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

OX Dovecot Pro is an email and collaboration server that uses OAuth2 for authentication. A flaw in its OAuth2 token validation allows attackers holding tokens with partial permissions to authenticate successfully when full permissions are required, bypassing configured authorization policies and potentially gaining unauthorized access to protected resources.

Technical details

The vulnerability is an authorization bypass in OAuth2 scope validation. When multiple scopes are required in the authorization configuration, the remote token validation path incorrectly accepts tokens carrying only one of the required scopes, while the local token validation path correctly enforces all scopes. This inconsistency allows an attacker with a partially-privileged OAuth2 token to authenticate successfully where they should be rejected. The attack requires possession of a valid OAuth2 token with reduced scope grants; no user interaction or local access is needed. The fix is to use local token validation exclusively or update to patched versions 2.3.22.2, 3.0.7, or 3.1.6.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0 to 2.3.22.1, 3.0.0 to 3.0.6, 3.1.0 to 3.1.5

Timeline

  • 2026-08-28: disclosed
  • 2026-08-26: advisory: OXDC-ADV-2026-0003 initial release
  • 2026-08-28: patched: Patched versions 2.3.22.2, 3.0.7, 3.1.6 released

References

Related threats