CVE-2026-27856 is a high-severity (CVSS 7.4) timing oracle vulnerability affecting Dovecot's doveadm component, which allows an unauthenticated attacker to determine configured credentials. Exploiting this vulnerability, despite its high complexity, could lead to full access to the affected component. There are no known public exploits, exploit code, or evidence of active exploitation, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.3CPE matchmatch criteria | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* | ||
< 2.3.22.1CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* | ||
>= 3.0.0, < 3.0.5CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* | ||
>= 3.1.0, < 3.1.4CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Dovecot vulnerabilities
Mar 31, 2026doveadm: Credentials verified without timing safety. Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials.
Mar 27, 2026