Improper access control in Dovecot and OX Dovecot Pro - CVE-2026-40020

 

Improper access control in Dovecot and OX Dovecot Pro - CVE-2026-40020

Published: May 19, 2026


Vulnerability identifier: #VU131868
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40020
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to spam folders to other users.

The vulnerability exists due to improper access control in the IMAP SETACL command when injecting the anyone permission into a user's dovecot-acl file. A remote user can use the IMAP SETACL command to spam folders to other users.

No unexpected access is gained.


Affected software

Dovecot
OX Dovecot Pro
Debian Linux
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
openEuler
Ubuntu
Fedora
dovecot22-backend-mysql-debuginfo
dovecot22-backend-sqlite-debuginfo
dovecot22-debugsource
dovecot22-backend-pgsql-debuginfo
dovecot22-backend-mysql
dovecot22-backend-pgsql
dovecot22
dovecot22-devel
dovecot22-debuginfo
dovecot22-backend-sqlite
dovecot (Ubuntu package)
dovecot (Debian package)
dovecot-devel
dovecot-help
dovecot-debugsource
dovecot-debuginfo
dovecot

How to mitigate CVE-2026-40020

Install security update from vendor's website.

Dovecot - update to 2.4.4
OX Dovecot Pro - update to 3.1.5
dovecot22-backend-mysql-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-sqlite-debuginfo - update to 2.2.31-19.37.2
dovecot22-debugsource - update to 2.2.31-19.37.2
dovecot22-backend-pgsql-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-mysql - update to 2.2.31-19.37.2
dovecot22-backend-pgsql - update to 2.2.31-19.37.2
dovecot22 - update to 2.2.31-19.37.2
dovecot22-devel - update to 2.2.31-19.37.2
dovecot22-debuginfo - update to 2.2.31-19.37.2
dovecot22-backend-sqlite - update to 2.2.31-19.37.2
dovecot (Ubuntu package) - addressed in versions 1:2.3.16+dfsg1-3ubuntu2.9, 1:2.3.21+dfsg1-2ubuntu6.5, 1:2.4.1+dfsg1-5ubuntu4.2, 1:2.4.2+dfsg1-3ubuntu2.1
dovecot (Debian package) - addressed in versions 1:2.3.19.1+dfsg1-2.1+deb12u6, 1:2.4.1+dfsg1-6+deb13u6
dovecot-devel - update to 2.3.20-5
dovecot-help - update to 2.3.20-5
dovecot-debugsource - update to 2.3.20-5
dovecot-debuginfo - update to 2.3.20-5
dovecot - update to 2.3.20-5
dovecot - addressed in versions 2.4.4-1.fc43, 2.4.4-1.fc44

External References

Related Security Bulletins