Remote Code Execution Vulnerability in Open-Xchange Dovecot
CVE-2026-40018
7.4HIGH
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-40018?
A critical security vulnerability has been identified in Open-Xchange's Dovecot application. This flaw allows for remote code execution, which could be exploited by malicious actors to gain unauthorized access or control over affected systems. Although no public exploits are currently known, the potential risk emphasizes the importance of timely updates and patch management to mitigate vulnerabilities in software applications.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 3.1.6
