PT-2026-40024 · Dovecot · Dovecot

Published

2026-05-12

·

Updated

2026-06-02

·

CVE-2026-27851

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.4-1.1
Description When the safe filter is used with variable expansion, subsequent pipelines on the same string are incorrectly treated as safe. This behavior allows unsafe data to be unescaped, which can lead to SQL or LDAP injection attacks during authentication.
Recommendations Update to version 2.4.4-1.1. Avoid using the safe filter until the update is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-27851
OPENSUSE-SU-2026:10766-1
USN-8365-1

Affected Products

Dovecot