CVE-2026-27860 Details
Description
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known.
A vulnerability exists in OX Dovecot when the 'auth_username_chars' parameter is left empty. This configuration allows the injection of arbitrary LDAP filters into Dovecot's LDAP authentication process. Such an injection could bypass existing restrictions and enable probing of the LDAP structure. The issue is present in OX Dovecot Pro versions 3.1.0, 3.1.2, 3.1.3, and 2.3.0, as well as OX Dovecot CE versions 2.4.0, 2.4.1, and 2.4.3. The vulnerability arises from improper input validation, specifically in how usernames are escaped in LDAP queries. No publicly available exploits are known.
Users are advised not to leave the 'auth_username_chars' parameter empty. Instead, it is recommended to install a fixed version of OX Dovecot. The latest versions can be obtained from the Open-Xchange website or through the Open-Xchange Update Catalog.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-90 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dovecot dovecot | < 2.4.3 |
CPE
Remediation
| |
| open-xchange dovecot | < 3.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |