PT-2026-40024 · Dovecot+2 · Dovecot+2

CVE-2026-27851

·

Published

2026-05-12

·

Updated

2026-07-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.4-1.1
Description When the safe filter is used with variable expansion, subsequent pipelines on the same string are incorrectly treated as safe. This behavior allows unsafe data to be unescaped, which can lead to SQL or LDAP injection attacks during authentication.
Recommendations Update to version 2.4.4-1.1. Avoid using the safe filter until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86799
CVE-2026-27851
OPENSUSE-SU-2026:10766-1
OPENSUSE-SU-2026:21109-1
SUSE-SU-2026:22185-1
USN-8365-1

Affected Products

Dovecot
Linuxmint
Ubuntu