CVE-2026-27851: SQL Injection
Last updated 2 June 2026
Other sources
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/dovecotto a version that resolves this vulnerability.Fixed in 1:2.3.13+dfsg1-2+deb11u1Fixed in 1:2.3.13+dfsg1-2+deb11u3Fixed in 1:2.3.19.1+dfsg1-2.1+deb12u5Fixed in 1:2.3.19.1+dfsg1-2.1+deb12u6Fixed in 1:2.4.1+dfsg1-6+deb13u6Fixed in 1:2.4.4+dfsg1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27851?
The severity of CVE-2026-27851 is critical with a CVSS score of 9.1.
How do I fix CVE-2026-27851?
To mitigate CVE-2026-27851, avoid using the safe filter with variable expansion in your applications.
What type of attacks does CVE-2026-27851 enable?
CVE-2026-27851 can enable SQL and LDAP injection attacks during authentication processes.
Which software is affected by CVE-2026-27851?
The affected software includes Dovecot, Open-Xchange Dovecot, and Debian/Dovecot.
When was CVE-2026-27851 published?
CVE-2026-27851 was published on May 12, 2026.