cbcvebase.
CVE-2026-24031
published 2026-03-27

CVE-2026-24031: Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user…

PriorityP353high8.2CVSS 3.1
AVNACLPRNUINSUCLIHAN
EPSS
0.40%
31.6th percentile
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:2.4.3+dfsg1-1 (sid)dovecot 1:2.4.3+dfsg1-1 (sid)
dovecotdovecot< 2.4.32.4.3
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-6+deb13u41:2.4.1+dfsg1-6+deb13u4
dovecotdovecot>= 0 < 1:2.3.16+dfsg1-3ubuntu2.71:2.3.16+dfsg1-3ubuntu2.7
dovecotdovecot>= 0 < 1:2.3.21+dfsg1-2ubuntu6.31:2.3.21+dfsg1-2ubuntu6.3
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-5ubuntu4.11:2.4.1+dfsg1-5ubuntu4.1
open-xchangedovecot< 3.1.43.1.4
open-xchange_gmbhox_dovecot_pro<= 3.1.0
ubuntudovecot

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
osv7.7HIGH
vendor_debian7.7LOW
vendor_redhat7.7HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.