CVE-2026-27860: Medium severity Dovecot Dovecot (LDAP authentication) vulnerability
If authusernamechars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and allows probing of LDAP structure. Do not clear out authusernamechars, or install fixed version. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27860?
CVE-2026-27860 has a high severity due to its potential for arbitrary LDAP filter injection which can lead to authentication bypass.
What are the consequences of CVE-2026-27860?
The consequence of CVE-2026-27860 includes unauthorized access and probing of the LDAP structure, which can compromise user data.
How do I fix CVE-2026-27860?
To fix CVE-2026-27860, ensure that the auth_username_chars configuration is not left empty and consider updating to a fixed version of Dovecot.
Is CVE-2026-27860 publicly exploitable?
No, there are currently no publicly available exploits for CVE-2026-27860.
What software is affected by CVE-2026-27860?
CVE-2026-27860 affects Dovecot, specifically the LDAP authentication module.