CVE-2026-0394: Path Traversal

Published Mar 27, 2026
·
Updated

When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path which ends with passwd). If this file contains passwords, it can be used to authenticate wrongly, or if this is userdb, it can unexpectly make system users appear valid users. Upgrade to fixed version, or use different authentication scheme that does not rely on paths. Alternatively you can also ensure that the per-domain passwd files are in some other location, such as /etc/dovecot/auth/%d. No publicly available exploits are known.

Affected Software

3 affected components
Dovecot dovecot
Dovecot dovecot<2.4.0
Open-Xchange Dovecot<3.1.0

Event History

Mar 27, 2026
CVE Published
via MITRE·08:10 AM
Data Sourced
via MITRE·08:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-0394?

The severity of CVE-2026-0394 is considered high due to the potential for unauthorized access to sensitive files.

2

How do I fix CVE-2026-0394?

To fix CVE-2026-0394, ensure that per-domain passwd files are not configured to be placed above the /etc directory.

3

What systems are affected by CVE-2026-0394?

CVE-2026-0394 affects Dovecot installations configured to use per-domain passwd files improperly.

4

What are the potential consequences of CVE-2026-0394?

The potential consequences of CVE-2026-0394 include the exposure of sensitive system files like /etc/passwd.

5

How can I prevent vulnerabilities like CVE-2026-0394 in the future?

To prevent vulnerabilities like CVE-2026-0394, always validate file paths and restrict configurations in Dovecot.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203