CVE-2026-40205
Last modified
CVE-2026-40205 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requires all of them. The configured authorization policy is not enforced, so a token that was granted only part of the required permissions is accepted where it should have been rejected. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requires all of them. The configured authorization policy is not enforced, so a token that was granted only part of the required permissions is accepted where it should have been rejected. Use local token validation where tokens can be validated locally. Update to non-vulnerable version. No publicly available exploits are known.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Open-Xchange GmbH | OX Dovecot Pro | >= 2.3.11.2, < 2.3.22.2; >= 3.0.0, < 3.0.7; >= 3.1.0, < 3.1.6 |
| Open-Xchange GmbH | OX Dovecot CE | >= 2.3.11.2, < 2.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40205?
How severe is CVE-2026-40205?
How do I fix CVE-2026-40205?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40199Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv…6.5
- CVE-2026-4020The Gravity SMTP plugin for WordPress is vulnerable to Sensi…7.5
- CVE-2026-40200An issue was discovered in musl libc 0.7.10 through 1.2.6. S…8.1
- CVE-2026-40201@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 al…5.4
- CVE-2026-40203When IMAP compression is enabled, the same compression state…3.7
- CVE-2026-40204None None None No publicly available exploits are known.3.1
- CVE-2026-40208An attacker might be able to delay the processing of DoH3 qu…3.7
- CVE-2026-40209An attacker might be able to cause outgoing TCP connections …5.3
- CVE-2026-4021The Contest Gallery plugin for WordPress is vulnerable to an…8.1
- CVE-2026-40210An out-of-bounds read might happen when SetMacAddrAction is …4.8
- CVE-2026-40211An attacker can send crafted DNS over HTTP/3 queries, trigge…5.3
- CVE-2026-40212OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-b…5.4
Are you affected by CVE-2026-40205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
