Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-27851 Details

Description

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-235Improper Handling of Extra Parameters[email protected]
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')redhat-SADP

Affected Products

ProductVersions
dovecot dovecot
< 2.4.4

CPE

  • cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
open-xchange dovecot
< 3.1.5

CPE

  • cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*

Remediation

  • No remediation found in references.

Change History

7 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-27851
NVD Published Date:
May 12, 2026
NVD Last Modified:
Jul 15, 2026
Source:
[email protected]
CVE-2026-27851 Details - Not Deferred