Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-27860: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') in Open-Xchange GmbH OX Dovecot Pro

0
Low
VulnerabilityCVE-2026-27860cvecve-2026-27860
Published: Fri Mar 27 2026 (03/27/2026, 08:10:22 UTC)
Source: CVE Database V5
Vendor/Project: Open-Xchange GmbH
Product: OX Dovecot Pro

Description

CVE-2026-27860 is an LDAP injection vulnerability in Open-Xchange GmbH's OX Dovecot Pro. It occurs if the configuration parameter auth_username_chars is empty, allowing injection of arbitrary LDAP filters during LDAP authentication. This can potentially bypass restrictions and enable probing of the LDAP structure. No public exploits are known, and the vulnerability has a low severity rating with a CVSS score of 3. 7.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/03/2026, 13:44:47 UTC

Technical Analysis

The vulnerability arises when the auth_username_chars setting in OX Dovecot Pro is empty, permitting an attacker to inject arbitrary LDAP filter expressions into the LDAP authentication process. This improper neutralization of special elements in LDAP queries can lead to bypassing authentication restrictions and reconnaissance of the LDAP directory structure. The issue is classified as LDAP injection. The CVSS 3.1 base score is 3.7, reflecting low impact with network attack vector, high attack complexity, no privileges required, no user interaction, unchanged scope, and low confidentiality impact. No known public exploits exist.

Potential Impact

Successful exploitation could allow an attacker to bypass certain LDAP authentication restrictions and probe the LDAP directory structure, potentially exposing sensitive directory information. However, the impact on confidentiality is rated low, and there is no impact on integrity or availability. No known exploits are publicly available.

Mitigation Recommendations

Do not configure auth_username_chars as empty. Alternatively, install a fixed version of OX Dovecot Pro when available. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
OX
Date Reserved
2026-02-24T08:46:09.374Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 69c63ffd3c064ed76f701ae4

Added to database: 3/27/2026, 8:29:49 AM

Last enriched: 4/3/2026, 1:44:47 PM

Last updated: 5/11/2026, 2:56:26 AM

Views: 74

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses