
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-52681 is a Denial of Service vulnerability in Open-Xchange Dovecot's Sieve script processing that allows authenticated attackers to bypass configured CPU resource limits and cause sustained resource exhaustion. The flaw was published on August 28, 2026, and affects OX Dovecot Pro versions 2.3.15–2.3.22.2, 3.0.0–3.0.7, and 3.1.0–3.1.6, as well as OX Dovecot CE versions 2.3.15–2.4.5. It carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, Red Hat Bugzilla).
The root cause is twofold and maps to CWE-1050 (Excessive Platform Resource Consumption within a Loop) and CWE-770 (Allocation of Resources Without Limits or Throttling). Dovecot tracks Sieve CPU usage within the compiled script object, meaning an authenticated user can reset the CPU accounting counter by repeatedly switching the active Sieve script, effectively circumventing the configured per-user CPU limit. Additionally, compiled script files are not cleaned up when a script is deleted or renamed, causing orphaned files to accumulate on disk. Both behaviors together enable an attacker to sustain high CPU load and grow disk consumption, degrading mail delivery service (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation degrades the availability of the mail delivery service by causing sustained CPU exhaustion and unbounded disk consumption on the affected Dovecot server. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. In multi-tenant or shared mail hosting environments, a single malicious authenticated user could degrade service for all other users on the same server (GitHub Advisory).
No publicly available proof-of-concept exploit code exists, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). Exploitation requires valid user credentials (low privileges), making it an authenticated attack with high complexity, which limits opportunistic abuse. The EPSS score is approximately 0.254% (17th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and NVD's SSVC assessment classifies exploitation as "none" (GitHub Advisory).
sieve-connect or a mail client with Sieve support) to authenticate to the server..svbin or similar compiled artifacts) in the Sieve script storage directory that do not correspond to any active or named user scripts; unexpected growth in disk usage in Sieve-related directories.SETACTIVE or script rename/delete ManageSieve commands in rapid succession; unusually high frequency of Sieve script compilation events for a single account.Upgrade to a fixed version: OX Dovecot Pro 2.3.22.2, 3.0.7, or 3.1.6; OX Dovecot CE 2.4.5 or later. No specific configuration-based workaround is documented, but administrators should monitor systems for abnormal CPU usage and disk consumption as interim detection measures. Restricting Sieve script management access to trusted users where operationally feasible can reduce exposure (GitHub Advisory, Red Hat Bugzilla).
The vulnerability was disclosed via the Open-Xchange security advisory and reported to Red Hat's Bugzilla as a low-severity issue. It was picked up by standard vulnerability tracking services including OSV, VulnDB, Tenable Nessus (plugin 341533), and Qualys shortly after publication. No notable researcher commentary or significant social media discussion has been observed, consistent with the low severity rating and absence of public exploits.
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
dovecot
devel
dovecot
focal (esm-infra)
dovecot
jammy
dovecot
noble
dovecot
resolute
dovecot
trusty (esm-infra-legacy)
dovecot
xenial (esm-infra-legacy)
dovecot
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."