OAuth2 Token Misconfiguration in Open-Xchange Dovecot Product
CVE-2026-40205

5.9MEDIUM

What is CVE-2026-40205?

A security flaw in Open-Xchange Dovecot allows an attacker to authenticate with an OAuth2 token that only partially meets the scope requirements. This occurs because the system mistakenly accepts tokens that do not possess all necessary permissions during remote token validation, while local validation correctly enforces complete scope requirements. This misconfiguration poses a risk as it allows unauthorized access. It is recommended to implement local token validation details and update to the secure version to mitigate potential threats.

Affected Version(s)

OX Dovecot CE 2.3.11.2 < 2.4.5

OX Dovecot Pro 2.3.11.2 < 2.3.22.2

OX Dovecot Pro 3.0.0 < 3.0.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.