Description
None None None No publicly available exploits are known.
Published: 2026-08-28
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to potential data disclosure
Action: Patch
AI Analysis

Impact

The vulnerability is classified as CWE‑89, indicating a SQL injection flaw that could allow an attacker to inject and execute arbitrary SQL commands. Because no publicly available exploits have been reported, the attack would require the attacker to discover and exploit the flaw manually. If successful, the attacker could gain unauthorized access to sensitive data stored in the database, potentially compromising confidentiality and data integrity of user information.

Affected Systems

The flaw affects Open‑Xchange Dovecot Community Edition (CE) and Open‑Xchange Dovecot Pro. No specific version range is supplied in the available data, so all deployed installations of these products may be at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 7.4 denotes a high severity, indicating that the vulnerability has a significant impact if exploited. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves exploitation of the Dovecot service over the network, requiring the attacker to craft a malicious SQL payload that is accepted by the application.

Generated by OpenCVE AI on August 28, 2026 at 14:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Open‑Xchange patch for OX Dovecot that addresses the SQL injection flaw as soon as it is released.
  • Restrict network access to the Dovecot service to trusted hosts or use a firewall or VPN to limit exposure.
  • Monitor database and application logs for anomalous SQL query activity and alert on suspicious patterns.

Generated by OpenCVE AI on August 28, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro
Vendors & Products Open-xchange
Open-xchange ox Dovecot Ce
Open-xchange ox Dovecot Pro

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Open-Xchange Dovecot SQL Injection Vulnerability dovecot: Dovecot: MySQL multi-byte escaping wrong
References
Metrics threat_severity

None

threat_severity

Important


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Open-Xchange Dovecot SQL Injection Vulnerability

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description None None None No publicly available exploits are known.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Open-xchange Ox Dovecot Ce Ox Dovecot Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: OX

Published:

Updated: 2026-08-28T15:00:32.995Z

Reserved: 2026-04-08T09:59:59.342Z

Link: CVE-2026-40018

cve-icon Vulnrichment

Updated: 2026-08-28T15:00:27.328Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:28.630

Modified: 2026-09-03T18:13:44.643

Link: CVE-2026-40018

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-28T10:12:20Z

Links: CVE-2026-40018 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:17:50Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')