OAuth2 Token Misconfiguration in Dovecot by Open-Xchange
CVE-2026-73208
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-73208?
An OAuth2 token misconfiguration in Dovecot allows an attacker to exploit tokens intended for different purposes. The vulnerability arises when a token response fails to include a scope claim, leading to the audience claim being improperly utilized to match configured scopes. This flaw permits acceptance of tokens that hold no relevant permissions, potentially granting unauthorized access. It highlights a significant identity provider misconfiguration where essential scope claims are omitted. Proper mitigative steps include ensuring all tokens have assigned scope claims and verifying that configured scope names do not correspond with audience values. This addresses the issue and enhances overall security posture.
Affected Version(s)
OX Dovecot CE 2.3.13 < 2.4.5
OX Dovecot Pro 2.3.13 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
