CVE-2026-52681
Dovecot vulnerability analysis and mitigation

Overview

CVE-2026-52681 is a Denial of Service vulnerability in Open-Xchange Dovecot's Sieve script processing that allows authenticated attackers to bypass configured CPU resource limits and cause sustained resource exhaustion. The flaw was published on August 28, 2026, and affects OX Dovecot Pro versions 2.3.15–2.3.22.2, 3.0.0–3.0.7, and 3.1.0–3.1.6, as well as OX Dovecot CE versions 2.3.15–2.4.5. It carries a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is twofold and maps to CWE-1050 (Excessive Platform Resource Consumption within a Loop) and CWE-770 (Allocation of Resources Without Limits or Throttling). Dovecot tracks Sieve CPU usage within the compiled script object, meaning an authenticated user can reset the CPU accounting counter by repeatedly switching the active Sieve script, effectively circumventing the configured per-user CPU limit. Additionally, compiled script files are not cleaned up when a script is deleted or renamed, causing orphaned files to accumulate on disk. Both behaviors together enable an attacker to sustain high CPU load and grow disk consumption, degrading mail delivery service (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation degrades the availability of the mail delivery service by causing sustained CPU exhaustion and unbounded disk consumption on the affected Dovecot server. There is no impact on confidentiality or integrity — the vulnerability is purely an availability issue. In multi-tenant or shared mail hosting environments, a single malicious authenticated user could degrade service for all other users on the same server (GitHub Advisory).

Exploitability

No publicly available proof-of-concept exploit code exists, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). Exploitation requires valid user credentials (low privileges), making it an authenticated attack with high complexity, which limits opportunistic abuse. The EPSS score is approximately 0.254% (17th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and NVD's SSVC assessment classifies exploitation as "none" (GitHub Advisory).

Exploitation steps

  1. Obtain valid credentials: The attacker must have a legitimate mail account on the target Dovecot server with Sieve script management access.
  2. Connect via ManageSieve: Use a ManageSieve client (e.g., sieve-connect or a mail client with Sieve support) to authenticate to the server.
  3. Upload and activate a Sieve script: Create and upload a Sieve script, then set it as the active script to trigger compilation and CPU accounting initialization.
  4. Reset CPU accounting in a loop: Repeatedly switch the active script (e.g., toggle between two uploaded scripts) to reset the CPU usage counter each time, bypassing the configured CPU limit and sustaining high CPU consumption.
  5. Accumulate orphaned compiled files: Delete or rename scripts without the server cleaning up compiled artifacts, causing disk usage to grow over time.
  6. Sustain the attack: Continue the loop to maintain elevated CPU load and disk consumption, degrading mail delivery for all users on the server (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • System Metrics: Abnormally high and sustained CPU utilization on the Dovecot server process without a corresponding spike in legitimate mail traffic.
  • File System: Accumulation of orphaned compiled Sieve script files (typically .svbin or similar compiled artifacts) in the Sieve script storage directory that do not correspond to any active or named user scripts; unexpected growth in disk usage in Sieve-related directories.
  • Logs: Dovecot logs showing a single authenticated user repeatedly issuing SETACTIVE or script rename/delete ManageSieve commands in rapid succession; unusually high frequency of Sieve script compilation events for a single account.
  • Network: High-frequency ManageSieve protocol (TCP port 4190) sessions from a single source IP authenticating and issuing script management commands in a tight loop (GitHub Advisory).

Mitigation and workarounds

Upgrade to a fixed version: OX Dovecot Pro 2.3.22.2, 3.0.7, or 3.1.6; OX Dovecot CE 2.4.5 or later. No specific configuration-based workaround is documented, but administrators should monitor systems for abnormal CPU usage and disk consumption as interim detection measures. Restricting Sieve script management access to trusted users where operationally feasible can reduce exposure (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was disclosed via the Open-Xchange security advisory and reported to Red Hat's Bugzilla as a low-severity issue. It was picked up by standard vulnerability tracking services including OSV, VulnDB, Tenable Nessus (plugin 341533), and Qualys shortly after publication. No notable researcher commentary or significant social media discussion has been observed, consistent with the low severity rating and absence of public exploits.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

dovecot

Affected

sid

dovecot: 1:2.4.5+dfsg1-1

Fixed

trixie

dovecot

Affected

Ubuntu

Unknown

bionic (esm-infra)

dovecot

Unknown

devel

dovecot

Unknown

focal (esm-infra)

dovecot

Unknown

jammy

dovecot

Unknown

noble

dovecot

Unknown

resolute

dovecot

Unknown

trusty (esm-infra-legacy)

dovecot

Unknown

xenial (esm-infra-legacy)

dovecot

Unknown

RHEL / CentOS

Affected

RHEL 8

dovecot.src

Affected

RHEL 9

dovecot.src

Affected

RHEL 10

dovecot.src

Affected

Alpine

Fixed

edge

dovecot: 2.4.5-r0

Fixed

v3.23

dovecot: 2.4.5-r0

Fixed

SourceThis report was generated using AI

Related Dovecot vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73208HIGH7.4
  • Dovecot logoDovecot
  • dovecot24-backend-sqlite
NoYesAug 28, 2026
CVE-2026-73209MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot24-fts-solr
NoYesAug 28, 2026
CVE-2026-52687MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot24-fts-flatcurve
NoYesAug 28, 2026
CVE-2026-42395MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot24
NoYesAug 28, 2026
CVE-2026-52681LOW3.1
  • Dovecot logoDovecot
  • dovecot24-fts-flatcurve
NoYesAug 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management