CVE-2026-40020: Medium severity Dovecot dovecot vulnerability
Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imapaclallowanyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40020?
CVE-2026-40020 is classified as a medium severity vulnerability, primarily affecting user experience rather than security.
How do I fix CVE-2026-40020?
To mitigate CVE-2026-40020, update your Dovecot installation to the fixed version provided in the latest security advisory.
What type of attack is associated with CVE-2026-40020?
CVE-2026-40020 allows attackers to exploit the IMAP SETACL command to inject permissions that cause folder spamming.
Will CVE-2026-40020 allow unauthorized access to my Dovecot server?
No, CVE-2026-40020 does not grant unauthorized access but enables spamming of folders to other users.
Who is affected by CVE-2026-40020?
Users of Dovecot who have enabled IMAP and are using the affected versions are susceptible to CVE-2026-40020.