No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 12 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Safe Filter in Open‑Xchange OX Dovecot Pro Enabling Injection Attacks | |
| First Time appeared |
Open-xchange
Open-xchange ox Dovecot Pro |
|
| Vendors & Products |
Open-xchange
Open-xchange ox Dovecot Pro |
Tue, 12 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known. | |
| Weaknesses | CWE-235 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-05-12T15:06:35.962Z
Reserved: 2026-02-24T08:46:09.372Z
Link: CVE-2026-27851
Updated: 2026-05-12T15:06:30.355Z
Status : Awaiting Analysis
Published: 2026-05-12T14:16:56.857
Modified: 2026-05-12T15:08:22.857
Link: CVE-2026-27851
No data.
OpenCVE Enrichment
Updated: 2026-05-12T15:30:18Z