Mail Data Manipulation Vulnerability in Dovecot by Open-Xchange
CVE-2026-33606
4.8MEDIUM
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-33606?
A vulnerability in Dovecot allows crafted mail content to be interpreted as dsync protocol commands by administrators during mail migration. This issue arises when untrusted content is processed, potentially resulting in unauthorized modifications to mailbox states and attributes. Administrators are advised to avoid executing dsync with the stream protocol on mailboxes that contain unverified content to prevent exploitation, and it is recommended to update to a secure version of the software.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
