Known Vulnerabilities for Dovecot by Open-xchange
Listed below are 10 of the newest known vulnerabilities associated with "Dovecot" by "Open-xchange".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73208 json | An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does ... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-42008 json | Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication ... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-42006 json | Not Provided | 2026-05-12 | 2026-08-03 | |
| CVE-2026-40020 json | Not Provided | 2026-05-12 | 2026-05-18 | |
| CVE-2026-40016 json | Not Provided | 2026-05-12 | 2026-05-18 | |
| CVE-2026-33604 json | An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafte... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-33603 json | Not Provided | 2026-05-12 | 2026-05-18 | |
| CVE-2026-27860 json | Not Provided | 2026-03-27 | 2026-04-29 | |
| CVE-2026-27859 json | Not Provided | 2026-03-27 | 2026-04-30 | |
| CVE-2026-27858 json | Not Provided | 2026-03-27 | 2026-07-15 |