VDB

CVE-2026-42008

CVE-2026-42008 PUBLISHED CVSS 4.3 MEDIUM

Reported by OX · Published August 28, 2026

Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any host permitted to act as a trusted proxy can authenticate as any user without knowing that user's password. This affects deployments whose password database honours a field that permits authentication without a password. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Open-Xchange GmbHOX Dovecot Pro2.3.4, 3.0.0, 3.1.0
Open-Xchange GmbHOX Dovecot CE2.3.4
Open-Xchange GmbHOX Dovecot Pro2.3.4, 3.0.0, 3.1.0
Open-Xchange GmbHOX Dovecot CE2.3.4

Timeline

  • Aug 28, 2026 CVE Published
  • Aug 29, 2026 EPSS Score
  • Sep 1, 2026 Security Advisory
  • Sep 3, 2026 CVE Updated
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 29, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score
  • Oct 7, 2026 EPSS Score

References

  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›