CVE-2026-40205

NameCVE-2026-40205
DescriptionAn attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requires all of them. The configured authorization policy is not enforced, so a token that was granted only part of the required permissions is accepted where it should have been rejected. Use local token validation where tokens can be validated locally. Update to non-vulnerable version. No publicly available exploits are known.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6526-1
Debian Bugs1146018

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dovecot (PTS)bookworm, bookworm (security)1:2.3.19.1+dfsg1-2.1+deb12u6vulnerable
trixie1:2.4.1+dfsg1-6+deb13u6vulnerable
trixie (security)1:2.4.1+dfsg1-6+deb13u7fixed
forky1:2.4.5+dfsg1-2fixed
sid1:2.4.5+dfsg1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dovecotsourcetrixie1:2.4.1+dfsg1-6+deb13u7DSA-6526-1
dovecotsource(unstable)1:2.4.5+dfsg1-11146018

Notes

https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-40205-oauth2-passdb-scope-enforcement-bypass-via-or-semantics-in-remote-validation-path
Same fixes for CVE-2026-40205 and CVE-2026-73208
Fixed by: https://github.com/dovecot/core/commit/4aa93054b6c9e4d0503e1cb78be36b389d2af98c
Fixed by: https://github.com/dovecot/core/commit/8518e3f62183b462bef645977b48af32e6701f6f
Fixed by: https://github.com/dovecot/core/commit/91b7a86a20f805301e8ea15715b246040c4d8cd9

Search for package or bug name: Reporting problems