CVE-2026-27858
Dovecot vulnerability analysis and mitigation

Overview

CVE-2026-27858 is a Denial of Service vulnerability in the Dovecot mail server's managesieve component that allows unauthenticated remote attackers to cause excessive memory allocation and crash the managesieve-login process. It was published on March 27, 2026, and affects Dovecot versions prior to 2.4.3 (community edition) and Open-Xchange Dovecot Pro versions prior to 2.3.22.1 (2.3.x branch), 3.0.5 (3.0.x branch), and 3.1.4 (3.1.x branch). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (OX Advisory, ENISA EUVD).

Technical details

The root cause is Uncontrolled Resource Consumption (CWE-400): the managesieve service fails to properly validate or limit the size of messages received before authentication, allowing a specially crafted pre-authentication message to trigger large memory allocations. By repeatedly sending such messages, an attacker can crash the managesieve-login process, rendering the service unavailable. No authentication or user interaction is required, and attack complexity is low, making this straightforward to exploit over the network (OX Advisory, oss-sec).

Impact

Successful exploitation results in a high availability impact: the managesieve-login process crashes and the ManageSieve protocol service (typically TCP port 4190) becomes unavailable, preventing users from managing their Sieve mail filtering scripts. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Repeated exploitation can sustain a persistent outage of the ManageSieve service (OX Advisory, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Dovecot servers with the ManageSieve service (TCP port 4190) exposed, using tools such as Shodan or Censys, targeting versions prior to 2.4.3 (community) or the relevant OX Dovecot Pro fixed versions.
  2. Connect to ManageSieve: Establish a TCP connection to port 4190 on the target server. The ManageSieve protocol presents a capability banner before authentication.
  3. Send crafted pre-authentication message: Before completing any authentication handshake, transmit a specially crafted message designed to trigger excessive memory allocation in the managesieve-login process. The exact payload structure is not publicly documented, but the vulnerability is triggered at the pre-authentication parsing stage.
  4. Crash the process: The managesieve-login process allocates a large amount of memory and crashes, causing the ManageSieve service to become unavailable.
  5. Repeat for sustained DoS: Repeatedly send the crafted message to prevent the service from recovering, sustaining a denial-of-service condition (OX Advisory, oss-sec).

Indicators of compromise

  • Network: Repeated inbound TCP connections to port 4190 (ManageSieve) from unexpected or external IP addresses, particularly connections that terminate abruptly without completing authentication.
  • Logs: Dovecot logs (typically /var/log/dovecot.log or /var/log/mail.log) showing repeated managesieve-login process crashes or restarts; error messages indicating out-of-memory conditions or abnormal process termination in the managesieve component.
  • Process: Frequent respawning of the managesieve-login process as observed via system process monitoring; elevated memory usage by managesieve-login prior to crash events.
  • System: Kernel OOM (Out of Memory) killer events logged in /var/log/kern.log or dmesg targeting the managesieve-login process.

Mitigation and workarounds

The primary remediation is to upgrade to a fixed version: Dovecot community edition 2.4.3 or later; OX Dovecot Pro 2.3.22.1 or later (2.3.x), 3.0.5 or later (3.0.x), or 3.1.4 or later (3.1.x) (OX Advisory). As a workaround prior to patching, restrict network access to the ManageSieve protocol (TCP port 4190) at the firewall or application level to trusted IP ranges only, limiting exposure to potential attackers. Patches have been distributed across major Linux distributions including Ubuntu (USN-8136-1, USN-8136-2), Debian (DSA-6197-1, DLA-4556-1), Red Hat (RHSA-2026:13498, RHSA-2026:13830, RHSA-2026:13857, and others), openSUSE, Amazon Linux 2023, and AlmaLinux (Ubuntu Advisory, Red Hat Errata).

Community reactions

The vulnerability was disclosed via the oss-security mailing list and Seclists Full Disclosure, generating standard community awareness (oss-sec, Full Disclosure). Multiple Linux distribution vendors (Red Hat, Ubuntu, Debian, openSUSE, Amazon Linux, AlmaLinux) responded promptly with security updates. Coverage was noted on security news aggregators and vulnerability tracking platforms, with no significant controversy or notable researcher commentary beyond standard patch advisories.

Additional resources


SourceThis report was generated using AI

Related Dovecot vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-27851CRITICAL9.1
  • Dovecot logoDovecot
  • dovecot
NoYesMay 12, 2026
CVE-2026-40016MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot-pigeonhole-debuginfo
NoYesMay 12, 2026
CVE-2026-33603MEDIUM5.3
  • Dovecot logoDovecot
  • dovecot24
NoYesMay 12, 2026
CVE-2026-42006MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot-mysql-debuginfo
NoYesMay 12, 2026
CVE-2026-40020MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot
NoYesMay 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management