CVE-2026-27856
Dovecot vulnerability analysis and mitigation

Overview

CVE-2026-27856 is a timing oracle vulnerability in Dovecot's doveadm credential verification that allows unauthenticated remote attackers to enumerate authentication credentials through response timing analysis. Affected software includes Dovecot versions before 2.4.3 (community edition) and Open-Xchange Dovecot Pro versions before 2.3.22.1, 3.0.0–3.0.4, and 3.1.0–3.1.3. The vulnerability was published on March 27, 2026, with patches made available shortly after. The CVSS v3.1 base score is 5.9 (Medium) per NVD, though the vendor (Open-Xchange) rates it 7.4 (High) using a vector that also includes integrity impact (OX Advisory, ENISA EUVD).

Technical details

The root cause is improper authentication (CWE-287) stemming from the use of a direct (non-constant-time) string comparison when verifying doveadm HTTP API credentials. This makes the comparison susceptible to a timing oracle attack, where an attacker can measure response time differences to iteratively determine the correct credential byte-by-byte. Exploitation requires only network access to the doveadm HTTP service port, with no privileges or user interaction needed, though the attack complexity is rated High due to the precision required for timing measurements. A technical write-up is available at Infinit Security (Infinit Security), and the vulnerability was also disclosed on the oss-security mailing list (oss-sec).

Impact

Successful exploitation allows an attacker to recover the doveadm HTTP API credentials, which then grants full administrative access to the doveadm component — the mail server administration interface. This compromises the confidentiality of authentication credentials and, once credentials are obtained, enables unauthorized control over mail server administration functions including potential access to user mailboxes, configuration changes, and further lateral movement within the mail infrastructure. Integrity and availability are not directly impacted by the timing oracle itself, but the credential disclosure effectively enables full compromise of the affected component (OX Advisory, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Dovecot instances with the doveadm HTTP service port exposed, using network scanning tools such as Shodan or Censys, targeting versions before 2.4.3 (community) or the affected OX Dovecot Pro versions.
  2. Baseline timing measurement: Send repeated authentication requests to the doveadm HTTP API endpoint with known-incorrect credentials to establish a baseline response time for failed authentication.
  3. Timing oracle enumeration: Iteratively send authentication requests varying one character of the credential at a time, measuring response times for each attempt. A statistically longer response time for a given character indicates a partial match due to the non-constant-time comparison.
  4. Credential recovery: Repeat the timing analysis for each character position until the full credential string is recovered, using statistical averaging to reduce noise from network jitter.
  5. Authenticate and gain access: Use the recovered credentials to authenticate to the doveadm HTTP API, gaining full administrative access to the mail server administration functions (Infinit Security, oss-sec).

Indicators of compromise

  • Network: High volume of repeated HTTP authentication requests to the doveadm HTTP service port (default: 8080 or configured port) from a single external IP address, especially with slight variations in credential parameters; unusual outbound connections from the mail server following doveadm API access.
  • Logs: Dovecot/doveadm access logs showing a large number of failed authentication attempts with incrementally varying credentials from the same source IP; successful doveadm API authentication from an unexpected or external IP address following a series of failures.
  • Process: Unexpected doveadm commands executed via the HTTP API (e.g., mailbox exports, user account modifications, configuration changes) from an unfamiliar source.

Mitigation and workarounds

Install the fixed versions immediately: Dovecot 2.4.3 (community), OX Dovecot Pro 2.3.22.1, 3.0.5, or 3.1.4 (OX Advisory). As an interim workaround, restrict network access to the doveadm HTTP service port to trusted hosts only using firewall rules or network segmentation. Distribution-specific patches are available for Ubuntu (USN-8136-1, USN-8136-2), Debian (DSA-6197-1, DLA-4556-1), openSUSE, and Amazon Linux 2023 (Ubuntu Advisory, Debian LTS, Amazon Linux).

Community reactions

The vulnerability was disclosed on the oss-security mailing list and Full Disclosure list, generating standard community awareness (oss-sec, Full Disclosure). Multiple Linux distributions including Ubuntu, Debian, openSUSE, and Amazon Linux issued security advisories and updated packages promptly. Tenable released multiple Nessus detection plugins (IDs 304114, 305037, 306220, 311199, 311743) to identify vulnerable systems (Tenable). No notable high-profile researcher commentary or significant social media discussion beyond routine CVE tracking was observed.

Additional resources


SourceThis report was generated using AI

Related Dovecot vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-27851CRITICAL9.1
  • Dovecot logoDovecot
  • dovecot
NoYesMay 12, 2026
CVE-2026-40016MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot-pigeonhole-debuginfo
NoYesMay 12, 2026
CVE-2026-33603MEDIUM5.3
  • Dovecot logoDovecot
  • dovecot24
NoYesMay 12, 2026
CVE-2026-42006MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot-mysql-debuginfo
NoYesMay 12, 2026
CVE-2026-40020MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot
NoYesMay 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management