CVE-2026-40016 Details
Description
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly available exploits are known.
A vulnerability exists in Open-Xchange Dovecot Pro and Community Edition versions 2.3.0, 3.0.5, 3.1.0, 3.1.4, and 3.1.5. This vulnerability allows an attacker to upload a malicious Sieve script via the ManageSieve service or locally, bypassing the configured CPU time limits for Sieve scripts. The exploitation can lead to a degradation of server performance, with the potential to exceed the normal CPU time limits by up to 130 times. No publicly available exploits are known.
Users are advised to update to the fixed version or, alternatively, prevent direct access to Sieve scripts via ManageSieve or local access.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0002.json | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dovecot dovecot | < 2.4.4 |
CPE
Remediation
| |
| open-xchange dovecot | < 3.1.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | [email protected] |