PT-2026-83054 · Dovecot · Dovecot

·

CVE-2026-33606

·

Published

2026-08-28

·

Updated

2026-09-02

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions dovecot versions prior to 2.4.5-1.1
Description Mail content stored by a user can be crafted to be interpreted as dsync protocol commands when an administrator executes dsync using the stream protocol, such as during migration or replication. This allows for the modification of mailbox states on the destination, including internal mailbox attributes that users should not be able to set directly, and may result in dsync errors.
Recommendations Update to version 2.4.5-1.1. Avoid running dsync with the stream protocol on mailboxes containing untrusted content.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98304
CVE-2026-33606
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1
SUSE-SU-2026:3919-1

Affected Products

Dovecot