---
cve: "CVE-2026-24031"
severity: "HIGH"
cvss: 7.7
epss: "40%"
vendor: "Open-Xchange GmbH"
kev: false
exploited: false
published: "2026-03-27 09:16:19"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-02T15:33:37+02:00"
---

# CVE-2026-24031

> 7.7 HIGH

## Beschreibung

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- c1b22ef978ca72999e254b2f3964b3d32d1a4979 (Commit)

## Referenzen

- <https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json>
- <https://access.redhat.com/security/cve/CVE-2026-24031>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2452181>
- <https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24031.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-24031) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
