CVE-2026-24031
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentic
CVSS
7.7
High
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Mar 27, 2026 · Last modified: Jul 15, 2026 · CWE-89
0.4%EPSS · 30 days0.4%
2026-08-242026-09-22
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits are known.
- documentation.open-xchange.comhttps://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-24031
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2452181
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24031.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-756829.9 CRI—
——0Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.4hCVE-2026-820119.1 CRI—
——0Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. Scope is changed.4hCVE-2026-820109.9 CRI—
——0Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.4hCVE-2026-820099.1 CRI—
——0Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL commands. Exploitation of this issue does not require user interaction. Scope is changed.4hCVE-2026-651288.8 HIG—
——0NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.4hCVE-2026-127189.8 CRI—
——0Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection.
This issue affects KarelIPS: through 22092026.
NOTE: The vendor was contacted and it was learned that the product is not supported.4h