Hosts vulnerable to CVE-2026-40020
CVE-2026-40020 — severity low, CVSS 3.1 — 2 affected hosts indexed by QROS Explore.
About CVE-2026-40020
Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed v
Showing 2 of 2 hosts, ranked by risk score.
1024.pl (5.9.174.104)
Germany · Falkenstein
14 open ports · 55 CVE · risk 98/100 · critical
ftp, http, imap, pop3, smtp, ssh
vps-226662f8.vps.ovh.net (57.128.168.198)
United Kingdom · Erith
12 open ports · 60 CVE · risk 98/100 · critical
ftp, http, imap, pop3, smtp, ssh
Search all CVE-2026-40020 hosts in Explore
Open in Explore →