{"apiVersion":"1.0","identifier":"CVE-2026-33606","description":"Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.","publishedAt":"2026-08-28T12:16:27","lastModifiedAt":"2026-08-28T12:16:27","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33606","cvssScore":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","epssProbability":0,"riskScore":0.48,"affectedProduct":"Dovecot","affectedVersions":"unknown","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-33606","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-33606","en":"https://www.redsauce.net/en/cves/CVE-2026-33606","fr":"https://www.redsauce.net/fr/cves/CVE-2026-33606","pt":"https://www.redsauce.net/pt/cves/CVE-2026-33606","de":"https://www.redsauce.net/de/cves/CVE-2026-33606","sk":"https://www.redsauce.net/sk/cves/CVE-2026-33606","el":"https://www.redsauce.net/el/cves/CVE-2026-33606"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-33606"}}