dovecot: Dovecot: Authentication bypass via trusted proxy forwarding
Published Aug 28, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.24%
Description
Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any host permitted to act as a trusted proxy can authenticate as any user without knowing that user's password. This affects deployments whose password database honours a field that permits authentication without a password. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.
Affected products
-
- Version 2.3.4StatusaffectedConstraints<2.4.5
- Version
-
- Version 2.3.4StatusaffectedConstraints<2.3.22.2
- Version 3.0.0StatusaffectedConstraints<3.0.7
- Version 3.1.0StatusaffectedConstraints<3.1.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Open-Xchange GmbH | OX Dovecot CE | unaffected |
| ||||||||||||
| Open-Xchange GmbH | OX Dovecot Pro | unaffected |
|
No data.
No data.
Red Hat Enterprise Linux 10
dovecot
Fix deferred
Red Hat Enterprise Linux 6
dovecot
Out of support scope
Red Hat Enterprise Linux 7
dovecot
Fix deferred
Red Hat Enterprise Linux 8
dovecot
Fix deferred
Red Hat Enterprise Linux 9
dovecot
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dovecot | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | dovecot | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | dovecot | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | dovecot | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | dovecot | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, ensure that the `auth_proxy_trusted_networks` configuration in Dovecot is strictly limited to only trusted hosts that are fully under administrative control. Review and restrict the `auth_proxy_trusted_networks` setting in your Dovecot configuration (e.g., `/etc/dovecot/conf.d/10-auth.conf` or similar) to prevent unauthorized hosts from acting as trusted proxies. If trusted proxies are not required, remove this configuration entirely. A restart of the Dovecot service may be required for changes to take effect.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-42008 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2525575 Issue Tracking
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0003.json vendor-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-67673 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42008
- https://www.cve.org/CVERecord?id=CVE-2026-42008
Change history (0)
No recorded changes yet.