cbcvebase.
CVE-2026-27855
published 2026-03-27

CVE-2026-27855: Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP…

PriorityP338medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.34%
26.3th percentile
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)
dovecotdovecot< 2.4.32.4.3
dovecotdovecot>= 0 < 1:2.3.19.1+dfsg1-2.1+deb12u21:2.3.19.1+dfsg1-2.1+deb12u2
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-6+deb13u41:2.4.1+dfsg1-6+deb13u4
dovecotdovecot>= 0 < 1:2.3.16+dfsg1-3ubuntu2.71:2.3.16+dfsg1-3ubuntu2.7
dovecotdovecot>= 0 < 1:2.3.21+dfsg1-2ubuntu6.31:2.3.21+dfsg1-2ubuntu6.3
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-5ubuntu4.11:2.4.1+dfsg1-5ubuntu4.1
open-xchangedovecot<= 2.3.0
open-xchange_gmbhox_dovecot_pro<= 2.3.0
ubuntudovecot

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.