CVE-2026-27860

NameCVE-2026-27860
DescriptionIf auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out auth_username_chars, or install fixed version. No publicly available exploits are known.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dovecot (PTS)bullseye1:2.3.13+dfsg1-2+deb11u1fixed
bullseye (security)1:2.3.13+dfsg1-2+deb11u2fixed
bookworm1:2.3.19.1+dfsg1-2.1+deb12u1fixed
bookworm (security)1:2.3.19.1+dfsg1-2.1+deb12u3fixed
trixie1:2.4.1+dfsg1-6+deb13u3vulnerable
trixie (security)1:2.4.1+dfsg1-6+deb13u4fixed
forky, sid1:2.4.3+dfsg1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dovecotsourcebullseye(not affected)
dovecotsourcebookworm(not affected)
dovecotsourcetrixie1:2.4.1+dfsg1-6+deb13u4
dovecotsource(unstable)1:2.4.3+dfsg1-1

Notes

[bookworm] - dovecot <not-affected> (Specific to 2.4.x)
[bullseye] - dovecot <not-affected> (Specific to 2.4.x)
https://dovecot.org/mailman3/archives/list/dovecot-news@dovecot.org/thread/IKIHZX77IPTGSP5WBIPJUOFBUQFKVPE7/
https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0001.html#cve-2026-27860-v2-4-v3-1-regression-auth-ldap-is-not-escaping-usernames
Fixed by: https://github.com/dovecot/core/commit/e2d8ef1ee04662e391e06ae76da1e7216c3a1fd3 (2.4.3)
Fixed by: https://github.com/dovecot/core/commit/6a8f2daf15727a36488252efc184dacaa7652cd2 (2.4.3)
Fixed by: https://github.com/dovecot/core/commit/34fbd3956db7f0ab1aefccb7750b4ec984681fa8 (2.4.3)
Fixed by: https://github.com/dovecot/core/commit/0e1f5abbbb27d7f8a485cd1c6a5673be995025a4 (2.4.3)
Fixed by: https://github.com/dovecot/core/commit/74a6f1612e7732026e69e8d8489291842df68589 (2.4.3)
Fixed by: https://github.com/dovecot/core/commit/25c34e50848155786d9a00eef6c310502f94e70f (2.4.3)
Fixed by: https://github.com/dovecot/core/commit/4049b0a8d5b6ca5c2cbcaadb9b5e81c3cce25044 (2.4.3)

Search for package or bug name: Reporting problems