Improper Handling of Extra Parameters in Dovecot and OX Dovecot Pro - CVE-2026-27851

 

Improper Handling of Extra Parameters in Dovecot and OX Dovecot Pro - CVE-2026-27851

Published: May 19, 2026


Vulnerability identifier: #VU131865
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27851
CWE-ID: CWE-235
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct SQL or LDAP injection attacks.

The vulnerability exists due to improper handling of extra parameters in lib-var-expand when using the safe filter with variable expansion. A remote attacker can supply unsafe data that is incorrectly treated as safe to conduct SQL or LDAP injection attacks.

This can occur when the vulnerable behavior is used in authentication.


Affected software

Dovecot
OX Dovecot Pro
Debian Linux
Ubuntu
Fedora
dovecot (Ubuntu package)
dovecot (Debian package)
dovecot

How to mitigate CVE-2026-27851

Install security update from vendor's website.

Dovecot - update to 2.4.4
OX Dovecot Pro - update to 3.1.5
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.9, 1:2.3.21+dfsg1-2ubuntu6.5, 1:2.4.1+dfsg1-5ubuntu4.2, 1:2.4.2+dfsg1-3ubuntu2.1
dovecot (Debian package) - addressed in versions 1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6
dovecot - addressed in versions 2.4.4-1.fc43, 2.4.4-1.fc44

External References

Related Security Bulletins