Junglewise Threat Intelligence

CVE-2026-42008: Open-Xchange Dovecot trusted proxy authentication bypass

CVE-2026-42008 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Technologies: Open-Xchange Dovecot Pro. Vendors: Open-Xchange.

Executive brief

Dovecot is an email server that handles user authentication and message storage for organizations. A flaw in how Dovecot processes authentication requests from trusted proxies allows any proxy server on the trusted list to authenticate as any user without knowing their password, potentially granting unauthorized access to email accounts. This vulnerability only affects deployments that have configured trusted proxies and use password databases that support passwordless authentication.

Technical details

The vulnerability is an authentication bypass caused by insufficient separation of forwarding information from trusted proxies and Dovecot's internal authentication fields. An attacker controlling a host on the trusted proxy list can inject forged authentication field values that allow login as any user without password verification. The attack requires network access to Dovecot and the host must be already whitelisted as a trusted proxy; it does not affect deployments without trusted proxy configuration. The vulnerability exists in Dovecot versions 2.3.0–2.3.22.1, 3.0.0–3.0.6, and 3.1.0–3.1.5, with patches available in versions 2.3.22.2, 3.0.7, and 3.1.6 respectively.

Affected products

  • Open-Xchange Dovecot Pro 2.3.0–2.3.22.1, 3.0.0–3.0.6, 3.1.0–3.1.5

Timeline

  • 2026-08-28: disclosed
  • 2026-08-28: patched: Patches available in versions 2.3.22.2, 3.0.7, and 3.1.6

References

Related threats