CVE-2025-30189 HIGH

CVE-2025-30189

Vendor Open-Xchange Gmbh
Product OX Dovecot Pro
Weakness CWE-1250
Published October 31, 2025
Last update March 27, 2026

CVSS base score

7.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally or for the impacted passdb/userdb drivers. No publicly available exploits are known.

Key dates

02Disclosure timeline

October 31, 2025 CVE published
March 27, 2026 Record updated