OAuth2 Token Misconfiguration in Open-Xchange Dovecot Product
CVE-2026-40205
5.9MEDIUM
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-40205?
A security flaw in Open-Xchange Dovecot allows an attacker to authenticate with an OAuth2 token that only partially meets the scope requirements. This occurs because the system mistakenly accepts tokens that do not possess all necessary permissions during remote token validation, while local validation correctly enforces complete scope requirements. This misconfiguration poses a risk as it allows unauthorized access. It is recommended to implement local token validation details and update to the secure version to mitigate potential threats.
Affected Version(s)
OX Dovecot CE 2.3.11.2 < 2.4.5
OX Dovecot Pro 2.3.11.2 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
