Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27858

29
FAUCET Score

CVE-2026-27858 is a denial-of-service vulnerability affecting systems utilizing the managesieve protocol. An unauthenticated attacker can send a specially crafted message to trigger excessive memory allocation, repeatedly crashing the managesieve-login process and rendering the service unavailable. This vulnerability carries a CVSS v3.1 score of 7.5 (High) due to its network-based, low-complexity attack vector and high impact on availability. Currently, there are no known public exploits or active exploitation, and exploit code is not available in common databases, though it has received limited community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.3CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
< 2.3.22.1CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
>= 3.0.0, < 3.0.5CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
>= 3.1.0, < 3.1.4CPE matchmatch criteria
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.79%
Probability of exploitation in next 30 days
EPSS Percentile
52.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0079 is in the 28th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

freeswitchpatch availablevia llm_extracted
View patch
ubuntupatch availablevia ubuntu_usn
Product: dovecot (jammy)Fixed in: 1:2.3.16+dfsg1-3ubuntu2.7
ubuntupatch availablevia ubuntu_usn
Product: dovecot (noble)Fixed in: 1:2.3.21+dfsg1-2ubuntu6.3
ubuntupatch availablevia ubuntu_usn
Product: dovecot (questing)Fixed in: 1:2.4.1+dfsg1-5ubuntu4.1

Vendor Advisories (2)

ubuntuUSN-8136-1

Dovecot vulnerabilities

Mar 31, 2026
freeswitchllm-freeswitch-dbea81d34366c3fd

managesieve-login out-of-memory DoS. Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.

Mar 27, 2026

References

access.redhat.com / errata/RHSA-2026:13498
access.redhat.com / errata/RHSA-2026:13830
access.redhat.com / errata/RHSA-2026:13857
access.redhat.com / errata/RHSA-2026:17602
access.redhat.com / errata/RHSA-2026:17625
access.redhat.com / errata/RHSA-2026:17626
access.redhat.com / errata/RHSA-2026:17628
access.redhat.com / errata/RHSA-2026:17630
access.redhat.com / errata/RHSA-2026:18053
access.redhat.com / errata/RHSA-2026:19149
access.redhat.com / errata/RHSA-2026:19364
access.redhat.com / errata/RHSA-2026:19453
access.redhat.com / errata/RHSA-2026:19455
access.redhat.com / errata/RHSA-2026:26564
access.redhat.com / security/cve/CVE-2026-27858
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-27858.json
documentation.open-xchange.com / dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0001.json
Vendor Advisory