
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40020 is an improper access control vulnerability in Dovecot IMAP server that allows authenticated attackers to bypass the imap_acl_allow_anyone=no configuration restriction via the IMAP SETACL command. By injecting the anyone permission into a target user's dovecot-acl file, an attacker can cause mailbox folders to be accessible and spammable to all users on the system. The vulnerability affects Dovecot versions prior to 2.4.4 and OX Dovecot Pro versions prior to 3.1.5. It was published on May 12, 2026, with a CVSS v3.1 base score of 4.3 (Medium) per NVD, or 3.1 (Low) per the GitHub Advisory Database and ENISA EUVD (GitHub Advisory, OX Advisory).
The root cause is classified as CWE-284 (Improper Access Control): Dovecot fails to properly enforce the imap_acl_allow_anyone=no configuration setting when processing IMAP SETACL commands. An authenticated IMAP user can craft a SETACL command that injects the anyone ACL identifier into another user's dovecot-acl file, effectively granting world-readable/writable access to that mailbox folder despite the administrator's intent to prohibit such permissions. Exploitation requires only low-level privileges (a valid IMAP account) and no user interaction, and is achievable over the network (GitHub Advisory, OX Advisory).
The primary impact is an availability and integrity degradation at the mailbox level: any authenticated IMAP user can spam folders to all other users on the mail server by manipulating ACL entries, bypassing the administrator-configured restriction. There is no confidentiality impact — no unauthorized data access or credential exposure is possible through this vulnerability — and no integrity impact on mail content itself. The scope is limited to the mail server's folder structure, with no evidence of lateral movement potential or privilege escalation (GitHub Advisory, OX Advisory).
openssl s_client or a standard IMAP client).anyone ACL permission.anyone identifier with desired rights (e.g., A001 SETACL user/victim/INBOX anyone lrswipkxtecda). Dovecot fails to block this despite imap_acl_allow_anyone=no being set.dovecot-acl file by issuing a GETACL command or checking server-side ACL files.anyone identifier from non-administrative user accounts; repeated SETACL operations targeting multiple users' mailboxes from a single authenticated session.anyone entries in dovecot-acl files within user mailbox directories (e.g., /var/mail/<user>/dovecot-acl or similar paths depending on mail storage layout); modification timestamps on dovecot-acl files that do not correspond to legitimate administrative activity.Upgrade Dovecot to version 2.4.4 or later, or OX Dovecot Pro to version 3.1.5 or later, which contain the fix for this vulnerability (OX Advisory). As a temporary workaround until patching is complete, restrict IMAP SETACL command permissions to trusted administrative users only and monitor dovecot-acl files for unauthorized anyone permission entries. Distribution-specific updates are available for Ubuntu (USN-8365-1), Debian (DLA-4617-1), openSUSE, and Fedora (Ubuntu Advisory, Debian Advisory).
The vulnerability was disclosed via the oss-security mailing list and Seclists Full Disclosure, indicating standard coordinated disclosure practices (oss-sec, Full Disclosure). Multiple Linux distributions including Ubuntu, Debian, openSUSE, and Fedora have issued security advisories and updated packages promptly following the disclosure. Community reaction has been measured given the limited impact scope — no data access is possible — with the primary concern being potential mail folder spam abuse in multi-tenant environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."