Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24031

30
FAUCET Score

CVE-2026-24031 is a high-severity SQL injection vulnerability (CWE-89) in Dovecot's SQL-based authentication, which occurs when the 'auth_username_chars' setting is cleared by an administrator. This flaw allows attackers to bypass authentication for any user and enumerate user accounts. Rated 7.7 (High) on CVSS, it has a network attack vector and high impact on confidentiality and integrity, despite requiring high attack complexity. Currently, there are no known public exploits, Metasploit modules, or Nuclei templates, and it is not on the KEV catalog or Hot List, though it has garnered minimal community discussion. Administrators should avoid clearing 'auth_username_chars' or apply the latest fixed version.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.3CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
< 3.1.4CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 12th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

freeswitchpatch availablevia llm_extracted
View patch
matrixpatch availablevia llm_extracted
View patch
ubuntupatch availablevia ubuntu_usn
Product: dovecot (jammy)Fixed in: 1:2.3.16+dfsg1-3ubuntu2.7
ubuntupatch availablevia ubuntu_usn
Product: dovecot (noble)Fixed in: 1:2.3.21+dfsg1-2ubuntu6.3
ubuntupatch availablevia ubuntu_usn
Product: dovecot (questing)Fixed in: 1:2.4.1+dfsg1-5ubuntu4.1

Vendor Advisories (3)

ubuntuUSN-8136-1

Dovecot vulnerabilities

Mar 31, 2026
freeswitchllm-freeswitch-e80b4505d5f8560d

v2.4/v3.1 regression: SQL injection allows bypassing authentication. Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin.

Mar 27, 2026
matrixllm-matrix-a49886e1724573e0

Dovecot vulnerabilities

References

access.redhat.com / security/cve/CVE-2026-24031
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-24031.json
documentation.open-xchange.com / dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
Vendor Advisory