IMAP Vulnerability in Open-Xchange Dovecot Product
CVE-2026-42392

4.3MEDIUM

What is CVE-2026-42392?

A vulnerability exists in Open-Xchange's Dovecot product where an attacker with valid credentials can exploit an invalid IMAP URLFETCH command. This can result in the inclusion of uninitialized memory in error responses sent to the client, leading to the possible disclosure of sensitive process memory contents. To mitigate this risk, it is advised to disable the IMAP URLAUTH functionality and to promptly update to a non-vulnerable version of the software.

Affected Version(s)

OX Dovecot CE 2.3.0 < 2.4.5

OX Dovecot Pro 2.3.0 < 3.1.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.