Bug 2525574 (CVE-2026-33606)
| Summary: | CVE-2026-33606 dovecot: Dovecot: Unauthorized mailbox modification via dsync command injection | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Dovecot. A malicious user can craft specific mail content that, when an administrator later uses the dsync tool with the stream protocol, is interpreted as dsync commands. This command injection allows the user to modify the state of mailboxes on the destination, including internal attributes that should not be directly accessible. This could lead to unauthorized data manipulation and potentially cause service disruptions.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2526670 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-28 11:23:48 UTC
|