User Authentication Flaw in OpenXchange Dovecot Product by OpenXchange
CVE-2025-30189 
7.4HIGH
What is CVE-2025-30189?
A flawed caching mechanism in OpenXchange Dovecot affects user identity verification. When caching is enabled, misconfigured passdb/userdb drivers cache all users using the same key, leading to the potential for incorrect user credentials to be accessed during subsequent logins. This vulnerability may result in users unknowingly gaining access to another user's session data. Users are advised to either update to the fixed version or disable caching for the affected drivers to mitigate the risk of unauthorized access. No public exploits for this flaw are currently available.
Affected Version(s)
OX Dovecot Pro 0 <= 2.4.0
