Impact
The vulnerability allows an attacker to bypass ACL restrictions when Dovecot automatically creates a mailbox, enabling unauthorized access to email data. It is an improper access control flaw (CWE‑1220 and CWE‑284) that could let a malicious user read or write messages that should be protected. No publicly available exploits are known, but the weakness could be exploited if the attacker can trigger automatic mailbox creation or otherwise influence the Dovecot configuration.
Affected Systems
Open‑Xchange’s OX Dovecot CE and OX Dovecot Pro are affected. The advisory does not specify particular product versions, indicating that all current builds of the Dovecot component which implements lda_mailbox_autocreate are potentially vulnerable. Administrators should verify whether their installations use either of these products.
Risk and Exploitability
The CVSS base score of 3.1 reflects low severity, and the EPSS score is below 1%, indicating a very low likelihood that this flaw will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly documented; it is inferred that exploitation may require either local or privileged access to the server's mailbox configuration or the ability to influence mailbox creation, but this cannot be confirmed from the available data.
OpenCVE Enrichment