CVE-2026-27858 is a denial-of-service vulnerability affecting systems utilizing the managesieve protocol. An unauthenticated attacker can send a specially crafted message to trigger excessive memory allocation, repeatedly crashing the managesieve-login process and rendering the service unavailable. This vulnerability carries a CVSS v3.1 score of 7.5 (High) due to its network-based, low-complexity attack vector and high impact on availability. Currently, there are no known public exploits or active exploitation, and exploit code is not available in common databases, though it has received limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.3CPE matchmatch criteria | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* | ||
< 2.3.22.1CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* | ||
>= 3.0.0, < 3.0.5CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* | ||
>= 3.1.0, < 3.1.4CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.