CVE-2026-24031

EUVD-2026-16561
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
dovecotdovecot
𝑥
< 2.4.3
open-xchangedovecot
𝑥
< 3.1.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dovecot
bookworm
1:2.3.19.1+dfsg1-2.1+deb12u1
fixed
bookworm (security)
1:2.3.19.1+dfsg1-2.1+deb12u4
fixed
bullseye
1:2.3.13+dfsg1-2+deb11u1
fixed
bullseye (security)
1:2.3.13+dfsg1-2+deb11u3
fixed
forky
1:2.4.3+dfsg1-2
fixed
sid
1:2.4.3+dfsg1-2
fixed
trixie
vulnerable
trixie (security)
1:2.4.1+dfsg1-6+deb13u4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dovecot
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
Fixed 1:2.4.1+dfsg1-5ubuntu4.1
released
trusty
not-affected
xenial
not-affected