
CVE-2026-27860 If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This leads to potentially bypassing restrictions and… https://www.cve.org/CVERecord?id=CVE-2026-27860
Post summary
CVE‑2026‑27860 permits LDAP filter injection via an empty 'auth_username_chars', enabling potential bypass of authentication restrictions in Dovecot.
