CVE-2026-27851 PUBLISHED

Assigner: OX
Reserved: 24.02.2026 Published: 12.05.2026 Updated: 12.05.2026

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 7.4

Product Status

Vendor Open-Xchange GmbH
Product OX Dovecot Pro
Versions Default: unaffected
  • affected from 0 to 3.1.4 (incl.)
  • affected from 0 to 2.4.3 (incl.)

References

Problem Types

  • Improper Handling of Extra Parameters cwe