CVE-2026-24031
published 2026-03-27CVE-2026-24031: Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user…
PriorityP353high8.2CVSS 3.1
AVNACLPRNUINSUCLIHAN
EPSS
0.40%
31.6th percentile
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.4.3+dfsg1-1 (sid) | dovecot 1:2.4.3+dfsg1-1 (sid) |
| dovecot | dovecot | < 2.4.3 | 2.4.3 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-6+deb13u4 | 1:2.4.1+dfsg1-6+deb13u4 |
| dovecot | dovecot | >= 0 < 1:2.3.16+dfsg1-3ubuntu2.7 | 1:2.3.16+dfsg1-3ubuntu2.7 |
| dovecot | dovecot | >= 0 < 1:2.3.21+dfsg1-2ubuntu6.3 | 1:2.3.21+dfsg1-2ubuntu6.3 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-5ubuntu4.1 | 1:2.4.1+dfsg1-5ubuntu4.1 |
| open-xchange | dovecot | < 3.1.4 | 3.1.4 |
| open-xchange_gmbh | ox_dovecot_pro | <= 3.1.0 | — |
| ubuntu | dovecot | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
osv7.7HIGH
vendor_debian7.7LOW
vendor_redhat7.7HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot regression
vendor_ubuntu·2026-04-28·CVSS 5.3
CVE-2026-0394 [MEDIUM] Dovecot regression
Title: Dovecot regression
Summary: USN-8136-1 introduced a regression in Dovecot
USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression
on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this i
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2026-03-31·CVSS 5.3
CVE-2026-27857 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. Thi
Red Hat
dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_chars configuration
vendor_redhat·2026-03-27·CVSS 7.7
CVE-2026-24031 [HIGH] CWE-89 dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_chars configuration
dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_chars configuration
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
A flaw was found in Dovecot. When the `auth_username_chars` configuration is cleared by an administrator, it creates an authentication bypass vulnerability. This allows a remote attacker to gain unauthorized access to user accounts and enumerate valid usernames.
Package: dovecot (Red Hat Enterprise Linux 10) - Affected
Package: dovecot (Red Hat Enterprise Linux 6) - Affec
Debian
CVE-2026-24031: dovecot - Dovecot SQL based authentication can be bypassed when auth_username_chars is cle...
vendor_debian·2026·CVSS 7.7
CVE-2026-24031 [HIGH] CVE-2026-24031: dovecot - Dovecot SQL based authentication can be bypassed when auth_username_chars is cle...
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
Scope: local
bookworm: resolved
bullseye: resolved
forky: open
sid: resolved (fixed in 1:2.4.3+dfsg1-1)
trixie: resolved (fixed in 1:2.4.1+dfsg1-6+deb13u4)
VulDB
Open-Xchange OX Dovecot Pro up to 2.4.0/3.1.0 auth_username_chars sql injection (adv-2026-0001 / Nessus ID 304090)
vuldb·2026-07-01·CVSS 8.2
CVE-2026-24031 [HIGH] Open-Xchange OX Dovecot Pro up to 2.4.0/3.1.0 auth_username_chars sql injection (adv-2026-0001 / Nessus ID 304090)
A vulnerability, which was classified as critical, has been found in Open-Xchange OX Dovecot Pro up to 2.4.0/3.1.0. This vulnerability affects unknown code. This manipulation of the argument auth_username_chars causes sql injection.
This vulnerability is handled as CVE-2026-24031. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
OSV
dovecot vulnerabilities
osv·2026-03-31·CVSS 5.3
CVE-2025-59028 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)
It was dis
OSV
CVE-2026-24031: Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin
osv·2026-03-27·CVSS 7.7
CVE-2026-24031 [HIGH] CVE-2026-24031: Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
GHSA
GHSA-fx6f-5qgf-9fmx: Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin
ghsa_unreviewed·2026-03-27
CVE-2026-24031 [HIGH] CWE-89 GHSA-fx6f-5qgf-9fmx: Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-24031 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-24031 [HIGH] CVE-2026-24031 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24031 :
Dovecot vulnerability analysis and mitigation
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
Source : NVD
## 7.7
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
Dovecot
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
dovecot
dovecot-devel
Sources
NVD
Alpine 3.23 Severity HIGH Has Fi
Bugzilla
CVE-2026-24031 dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_chars configuration
bugzilla·2026-03-27·CVSS 7.7
CVE-2026-24031 [HIGH] CVE-2026-24031 dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_chars configuration
CVE-2026-24031 dovecot: Dovecot: Authentication bypass and user enumeration due to cleared auth_username_chars configuration
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
2026-03-27
Published