CVE-2026-27858 Details
Description
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.
A vulnerability exists in Open-Xchange Dovecot Pro and Community Edition versions 2.4.0 prior to 2.4.3 and 3.1.0, as well as in Dovecot Pro 2.3.0, that allows an attacker to send a specially crafted message before authentication. This message causes the ManageSieve service to allocate a large amount of memory, leading to a denial-of-service condition. The process can be crashed repeatedly, causing the ManageSieve login to become unavailable for other users.
Users are advised to protect access to the ManageSieve protocol or to upgrade to a fixed version. Instructions for updating can be found in the Open-Xchange Dovecot security advisory OXDC-ADV-2026-0001.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-770 | Allocation of Resources Without Limits or Throttling | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| dovecot dovecot | < 2.4.3 |
CPE
Remediation
| |
| open-xchange dovecot | < 2.3.22.1 >= 3.0.0, < 3.0.5 >= 3.1.0, < 3.1.4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |