Hosts vulnerable to CVE-2026-40020

CVE-2026-40020 — severity low, CVSS 3.1 — 2 affected hosts indexed by QROS Explore.

About CVE-2026-40020

Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed v

Showing 2 of 2 hosts, ranked by risk score.

Search all CVE-2026-40020 hosts in Explore

Open in Explore →