CVE-2026-27856 | Open-Xchange OX Dovecot Pro up to 2.3.0 Doveadm Http Service improper authentication (adv-2026-0001 / Nessus ID 304114)
A vulnerability was found in Open-Xchange OX Dovecot Pro up to 2.3.0. It has been rated as critical. The affected element is an unknown function of the component Doveadm Http Service. The manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-27856. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.