Path Traversal Vulnerability in Dovecot Authentication by Open-Xchange
CVE-2026-0394
5.3MEDIUM
What is CVE-2026-0394?
A vulnerability exists in Dovecot when configured to use per-domain password files located one path component above /etc, or if a slash has been included in allowed characters. This misconfiguration can lead to path traversal issues, allowing unauthorized access to sensitive files such as /etc/passwd. If exploited, this can enable unintended authentication behaviors or misrepresent system users as valid users. To mitigate this risk, it is recommended to upgrade to a fixed version, utilize an alternative authentication mechanism that does not depend on file paths, or store per-domain password files in a safer location, such as /etc/dovecot/auth/%d.
Affected Version(s)
OX Dovecot Pro 0 <= 2.3.0
