
CVE-2026-0394 When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path … https://www.cve.org/CVERecord?id=CVE-2026-0394
Post summary
The text announces a new CVE‑2026‑0394 vulnerability in Dovecot, detailing the configuration flaw that enables path traversal, but it does not mention exploits, patches, or active attacks.
