PT-2026-83074 · Dovecot · Dovecot
CVE-2026-73208
·
Published
2026-08-28
·
Updated
2026-09-01
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dovecot versions prior to 2.4.5-1.1
Description
An authentication flaw exists where a token intended for a different purpose can be used to authenticate. This occurs when an OAuth2 token response lacks a scope claim, causing the system to use the audience claim instead and validate it against the configured required scopes. Because the audience claim identifies the intended recipient rather than the permitted actions, a token without relevant permissions may be accepted if its recipient value matches a configured scope name. This behavior also masks identity provider misconfigurations where scopes are not issued.
Recommendations
Update to version 2.4.5-1.1.
Ensure the identity provider issues a scope claim for all tokens used with Dovecot.
Configure scope names so they do not match audience values.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dovecot