CVE-2026-42392: Open-Xchange GmbH Ox Dovecot CE
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to non-vulnerable version. No publicly available exploits are known.
Affected products
- Open-Xchange GmbH Ox Dovecot CE: from 2.3.0, before 2.4.5 (fixed in 2.4.5)
- Open-Xchange GmbH Ox Dovecot Pro: from 2.3.0, before 3.1.6 (fixed in 3.1.6)
Published 2026-08-28. Last modified 2026-09-03.