
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27860 is an LDAP injection vulnerability in Dovecot's LDAP authentication mechanism that allows unauthenticated remote attackers to inject arbitrary LDAP filter characters when the auth_username_chars configuration parameter is empty. It affects Dovecot versions prior to 2.4.3 and Open-Xchange Dovecot Pro versions prior to 3.1.4. The vulnerability was published on March 27, 2026, with a patch advisory released by Open-Xchange. It carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, though ENISA's EUVD rates it 3.7 (Low) under a higher attack complexity assumption (OX Advisory, EUVD).
The root cause is improper neutralization of special elements used in an LDAP query (CWE-90 / LDAP Injection, CAPEC-136). When the auth_username_chars configuration option is set to an empty value in Dovecot, the username field passed to the LDAP authentication backend is not sanitized, allowing an attacker to embed arbitrary LDAP filter syntax (e.g., parentheses, wildcards, logical operators) into the username string. This crafted input is then interpreted by the LDAP server as part of the filter expression, enabling filter manipulation. No authentication, user interaction, or special privileges are required to exploit this vulnerability over the network (OX Advisory, oss-sec).
Successful exploitation allows a network attacker to probe and enumerate the LDAP directory structure, potentially identifying valid usernames, organizational units, and other directory attributes. Additionally, authentication restrictions may be bypassed by crafting LDAP filters that alter the authentication logic (e.g., forcing a filter to always evaluate as true). The primary confirmed impact is low-level information disclosure (confidentiality: low); integrity and availability are not directly affected. The vulnerability scope is limited to systems where Dovecot is configured to use LDAP authentication with auth_username_chars explicitly cleared (OX Advisory, EUVD).
auth_username_chars set to an empty value — this is the required misconfiguration. Default Dovecot installations restrict username characters, so this requires a deliberate configuration change.*, (, ), \, |, &) to inject into the LDAP filter. For example, a username like *)(uid=*))(|(uid=* could manipulate the LDAP filter logic./var/log/mail.log or /var/log/dovecot.log) showing login attempts with usernames containing LDAP special characters such as *, (, ), |, &, or \.Upgrade Dovecot to version 2.4.3 or later, or upgrade Open-Xchange Dovecot Pro to version 3.1.4 or later to receive the official fix (OX Advisory). As an immediate workaround, ensure the auth_username_chars configuration parameter is not set to an empty value — retaining the default character restrictions prevents injection of LDAP special characters. Ubuntu users should apply the patches provided in USN-8136-1 and USN-8136-2 (Ubuntu USN-8136-1, Ubuntu USN-8136-2). openSUSE users should apply the security updates announced via the openSUSE security mailing list (openSUSE Advisory). Debian users should apply DSA-6197-1 as covered by downstream advisories.
The vulnerability was disclosed via the oss-security mailing list and Full Disclosure list in March 2026, generating moderate community attention (oss-sec, Full Disclosure). Major Linux distributions including Ubuntu, openSUSE, and Debian issued security advisories and updated packages relatively promptly after disclosure. Security scanner vendors Tenable (Nessus) and Qualys added detection plugins shortly after the advisory was published. Overall community sentiment treats this as a low-to-medium severity issue given the non-default precondition required for exploitation and the absence of known active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."