If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LDAP Filter Injection in Open‑Xchange OX Dovecot Pro |
Fri, 27 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known. | |
| Weaknesses | CWE-90 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-03-27T08:10:22.695Z
Reserved: 2026-02-24T08:46:09.374Z
Link: CVE-2026-27860
No data.
Status : Received
Published: 2026-03-27T09:16:20.383
Modified: 2026-03-27T09:16:20.383
Link: CVE-2026-27860
No data.
OpenCVE Enrichment
Updated: 2026-03-27T09:45:42Z