CVE-2026-27851 Details
Description
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
A vulnerability exists in Open-Xchange Dovecot Pro and Community Edition when the safe filter is applied with variable expansion. This combination allows all subsequent pipelines on the same string to be misinterpreted as safe, enabling the unescaping of unsafe data. Such behavior can facilitate SQL or LDAP injection attacks during authentication. The issue is present in OX Dovecot Pro versions 3.1.4, 3.1.0, and 3.0.5, as well as OX Dovecot CE versions 2.4.3 and 2.4.0.
Users are advised to avoid using the safe filter until they have updated to a fixed version. The vulnerability has been addressed in OX Dovecot Pro 3.1.5 and OX Dovecot CE 2.4.4.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-235 | Improper Handling of Extra Parameters | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| dovecot dovecot | < 2.4.4 |
CPE
Remediation
| |
| open-xchange dovecot | < 3.1.5 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 10, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 18, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |