#VU124725 LDAP injection in Dovecot and OX Dovecot Pro - CVE-2026-27860
Published: April 1, 2026
Dovecot
OX Dovecot Pro
Dovecot
Description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper neutralization of special elements in an LDAP query within the auth-ldap module when processing usernames. A remote attacker can send a specially crafted request with malicious username when auth_username_chars is empty to probe LDAP structure and potentially bypass authentication.
The server must have auth_username_chars configuration option cleared.