CVE-2026-40020
CVE-2026-40020 is a low-severity vulnerability in Open-xchange Dovecot with a CVSS 3.x base score of 3.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Low (CVSS 3.x base score 3.1)
- EPSS exploit prediction: 0% (20th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-29471
- Weakness: CWE-284
- Affected product: Open-xchange Dovecot
- Published:
- Last modified:
Description
Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.
Frequently asked questions
- What is CVE-2026-40020?
- Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.
- How severe is CVE-2026-40020?
- CVE-2026-40020 has a CVSS 3.x base score of 3.1, rated low severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-40020 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (20th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-40020?
- CVE-2026-40020 primarily affects Open-xchange Dovecot. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-40020?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-40020 have an EU (EUVD) identifier?
- Yes. CVE-2026-40020 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-29471.
- When was CVE-2026-40020 published?
- CVE-2026-40020 was published on 2026-05-12 and last updated on 2026-06-17.
References
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json
Affected products (2)
- cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
- cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
More vulnerabilities in Open-xchange Dovecot
- CVE-2026-24031 — High (CVSS 7.7): Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability…
- CVE-2026-27858 — High (CVSS 7.5): Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount…
- CVE-2025-59032 — High (CVSS 7.5): ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash…
- CVE-2026-27851 — High (CVSS 7.4): When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly…
- CVE-2026-27856 — High (CVSS 7.4): Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can…
- CVE-2026-33603 — Medium (CVSS 6.8): Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This…
All CVEs affecting Open-xchange Dovecot →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-83944 — Critical (CVSS 10.0): Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-20192 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine…
- CVE-2026-87230 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-54745 — Critical (CVSS 10.0): Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0,…
- CVE-2026-18886 — Critical (CVSS 10.0): ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform.…
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
Browse all CWE-284 (Improper Access Control) vulnerabilities →