PT-2026-83074 · Dovecot · Dovecot

CVE-2026-73208

·

Published

2026-08-28

·

Updated

2026-09-01

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dovecot versions prior to 2.4.5-1.1
Description An authentication flaw exists where a token intended for a different purpose can be used to authenticate. This occurs when an OAuth2 token response lacks a scope claim, causing the system to use the audience claim instead and validate it against the configured required scopes. Because the audience claim identifies the intended recipient rather than the permitted actions, a token without relevant permissions may be accepted if its recipient value matches a configured scope name. This behavior also masks identity provider misconfigurations where scopes are not issued.
Recommendations Update to version 2.4.5-1.1. Ensure the identity provider issues a scope claim for all tokens used with Dovecot. Configure scope names so they do not match audience values.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98295
CVE-2026-73208
OPENSUSE-SU-2026:11629-1
OPENSUSE-SU-2026:21720-1

Affected Products

Dovecot