IMAP Vulnerability in Open-Xchange Dovecot Product
CVE-2026-42392
4.3MEDIUM
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-42392?
A vulnerability exists in Open-Xchange's Dovecot product where an attacker with valid credentials can exploit an invalid IMAP URLFETCH command. This can result in the inclusion of uninitialized memory in error responses sent to the client, leading to the possible disclosure of sensitive process memory contents. To mitigate this risk, it is advised to disable the IMAP URLAUTH functionality and to promptly update to a non-vulnerable version of the software.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 3.1.6
