
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27856 is a timing oracle vulnerability in Dovecot's doveadm credential verification that allows unauthenticated remote attackers to enumerate authentication credentials through response timing analysis. Affected software includes Dovecot versions before 2.4.3 (community edition) and Open-Xchange Dovecot Pro versions before 2.3.22.1, 3.0.0–3.0.4, and 3.1.0–3.1.3. The vulnerability was published on March 27, 2026, with patches made available shortly after. The CVSS v3.1 base score is 5.9 (Medium) per NVD, though the vendor (Open-Xchange) rates it 7.4 (High) using a vector that also includes integrity impact (OX Advisory, ENISA EUVD).
The root cause is improper authentication (CWE-287) stemming from the use of a direct (non-constant-time) string comparison when verifying doveadm HTTP API credentials. This makes the comparison susceptible to a timing oracle attack, where an attacker can measure response time differences to iteratively determine the correct credential byte-by-byte. Exploitation requires only network access to the doveadm HTTP service port, with no privileges or user interaction needed, though the attack complexity is rated High due to the precision required for timing measurements. A technical write-up is available at Infinit Security (Infinit Security), and the vulnerability was also disclosed on the oss-security mailing list (oss-sec).
Successful exploitation allows an attacker to recover the doveadm HTTP API credentials, which then grants full administrative access to the doveadm component — the mail server administration interface. This compromises the confidentiality of authentication credentials and, once credentials are obtained, enables unauthorized control over mail server administration functions including potential access to user mailboxes, configuration changes, and further lateral movement within the mail infrastructure. Integrity and availability are not directly impacted by the timing oracle itself, but the credential disclosure effectively enables full compromise of the affected component (OX Advisory, ENISA EUVD).
Install the fixed versions immediately: Dovecot 2.4.3 (community), OX Dovecot Pro 2.3.22.1, 3.0.5, or 3.1.4 (OX Advisory). As an interim workaround, restrict network access to the doveadm HTTP service port to trusted hosts only using firewall rules or network segmentation. Distribution-specific patches are available for Ubuntu (USN-8136-1, USN-8136-2), Debian (DSA-6197-1, DLA-4556-1), openSUSE, and Amazon Linux 2023 (Ubuntu Advisory, Debian LTS, Amazon Linux).
The vulnerability was disclosed on the oss-security mailing list and Full Disclosure list, generating standard community awareness (oss-sec, Full Disclosure). Multiple Linux distributions including Ubuntu, Debian, openSUSE, and Amazon Linux issued security advisories and updated packages promptly. Tenable released multiple Nessus detection plugins (IDs 304114, 305037, 306220, 311199, 311743) to identify vulnerable systems (Tenable). No notable high-profile researcher commentary or significant social media discussion beyond routine CVE tracking was observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."