CVE-2026-0394
published 2026-03-27CVE-2026-0394: When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.43%
35.0th percentile
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm) | dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm) |
| dovecot | dovecot | < 2.4.0 | 2.4.0 |
| dovecot | dovecot | >= 0 < 1:2.3.19.1+dfsg1-2.1+deb12u2 | 1:2.3.19.1+dfsg1-2.1+deb12u2 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-1 | 1:2.4.1+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-1 | 1:2.4.1+dfsg1-1 |
| dovecot | dovecot | >= 0 < 1:2.3.16+dfsg1-3ubuntu2.7 | 1:2.3.16+dfsg1-3ubuntu2.7 |
| dovecot | dovecot | >= 0 < 1:2.3.21+dfsg1-2ubuntu6.3 | 1:2.3.21+dfsg1-2ubuntu6.3 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-5ubuntu4.1 | 1:2.4.1+dfsg1-5ubuntu4.1 |
| open-xchange | dovecot | < 3.1.0 | 3.1.0 |
| open-xchange_gmbh | ox_dovecot_pro | <= 2.3.0 | — |
| ubuntu | dovecot | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot regression
vendor_ubuntu·2026-04-28·CVSS 5.3
CVE-2026-0394 [MEDIUM] Dovecot regression
Title: Dovecot regression
Summary: USN-8136-1 introduced a regression in Dovecot
USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression
on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this i
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2026-03-31·CVSS 5.3
CVE-2026-27857 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. Thi
Red Hat
dovecot: Dovecot: Information disclosure and authentication bypass via path traversal
vendor_redhat·2026-03-27·CVSS 5.3
CVE-2026-0394 [MEDIUM] CWE-22 dovecot: Dovecot: Information disclosure and authentication bypass via path traversal
dovecot: Dovecot: Information disclosure and authentication bypass via path traversal
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly avail
Debian
CVE-2026-0394: dovecot - When dovecot has been configured to use per-domain passwd files, and they are pl...
vendor_debian·2026·CVSS 5.3
CVE-2026-0394 [MEDIUM] CVE-2026-0394: dovecot - When dovecot has been configured to use per-domain passwd files, and they are pl...
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known.
Scope: local
bookworm: resolved (fixed in 1:2.3.19.1+dfsg1-2.1
OSV
dovecot vulnerabilities
osv·2026-03-31·CVSS 5.3
CVE-2025-59028 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)
It was dis
OSV
CVE-2026-0394: When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed
osv·2026-03-27·CVSS 5.3
CVE-2026-0394 [MEDIUM] CVE-2026-0394: When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known.
GHSA
GHSA-xmp7-q4wc-cq3x: When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed
ghsa_unreviewed·2026-03-27
CVE-2026-0394 [MEDIUM] CWE-22 GHSA-xmp7-q4wc-cq3x: When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known.
No detection rules found.
No public exploits indexed.
2026-03-27
Published