CVE-2026-27855 Details
Description
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
A replay attack vulnerability has been identified in OX Dovecot authentication using One-Time Passwords (OTP). This issue arises under specific conditions: when the authentication cache is enabled and the username is modified in the password database. In such cases, OTP credentials can be cached, allowing the same OTP response to be reused for authentication. An attacker who observes an OTP exchange can exploit this vulnerability to log in as the user. This vulnerability affects OX Dovecot Pro versions 2.3.0, 3.0.2, 3.1.0, and OX Dovecot CE versions 2.4.0, 2.4.1, and 2.4.3.
Users should switch to a secure connection and, if possible, use the SCRAM protocol for authentication. For those on OX Dovecot Pro 2.3.0, the authentication cache can be disabled or the application can be upgraded to a fixed version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dovecot dovecot | < 2.4.3 |
CPE
Remediation
| |
| open-xchange dovecot | <= 2.3.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |