
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27858 is a Denial of Service vulnerability in the Dovecot mail server's managesieve component that allows unauthenticated remote attackers to cause excessive memory allocation and crash the managesieve-login process. It was published on March 27, 2026, and affects Dovecot versions prior to 2.4.3 (community edition) and Open-Xchange Dovecot Pro versions prior to 2.3.22.1 (2.3.x branch), 3.0.5 (3.0.x branch), and 3.1.4 (3.1.x branch). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (OX Advisory, ENISA EUVD).
The root cause is Uncontrolled Resource Consumption (CWE-400): the managesieve service fails to properly validate or limit the size of messages received before authentication, allowing a specially crafted pre-authentication message to trigger large memory allocations. By repeatedly sending such messages, an attacker can crash the managesieve-login process, rendering the service unavailable. No authentication or user interaction is required, and attack complexity is low, making this straightforward to exploit over the network (OX Advisory, oss-sec).
Successful exploitation results in a high availability impact: the managesieve-login process crashes and the ManageSieve protocol service (typically TCP port 4190) becomes unavailable, preventing users from managing their Sieve mail filtering scripts. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Repeated exploitation can sustain a persistent outage of the ManageSieve service (OX Advisory, ENISA EUVD).
/var/log/dovecot.log or /var/log/mail.log) showing repeated managesieve-login process crashes or restarts; error messages indicating out-of-memory conditions or abnormal process termination in the managesieve component.managesieve-login process as observed via system process monitoring; elevated memory usage by managesieve-login prior to crash events./var/log/kern.log or dmesg targeting the managesieve-login process.The primary remediation is to upgrade to a fixed version: Dovecot community edition 2.4.3 or later; OX Dovecot Pro 2.3.22.1 or later (2.3.x), 3.0.5 or later (3.0.x), or 3.1.4 or later (3.1.x) (OX Advisory). As a workaround prior to patching, restrict network access to the ManageSieve protocol (TCP port 4190) at the firewall or application level to trusted IP ranges only, limiting exposure to potential attackers. Patches have been distributed across major Linux distributions including Ubuntu (USN-8136-1, USN-8136-2), Debian (DSA-6197-1, DLA-4556-1), Red Hat (RHSA-2026:13498, RHSA-2026:13830, RHSA-2026:13857, and others), openSUSE, Amazon Linux 2023, and AlmaLinux (Ubuntu Advisory, Red Hat Errata).
The vulnerability was disclosed via the oss-security mailing list and Seclists Full Disclosure, generating standard community awareness (oss-sec, Full Disclosure). Multiple Linux distribution vendors (Red Hat, Ubuntu, Debian, openSUSE, Amazon Linux, AlmaLinux) responded promptly with security updates. Coverage was noted on security news aggregators and vulnerability tracking platforms, with no significant controversy or notable researcher commentary beyond standard patch advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."