CVE-2026-27855
published 2026-03-27CVE-2026-27855: Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP…
PriorityP338medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.34%
26.3th percentile
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dovecot | < dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm) | dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm) |
| dovecot | dovecot | < 2.4.3 | 2.4.3 |
| dovecot | dovecot | >= 0 < 1:2.3.19.1+dfsg1-2.1+deb12u2 | 1:2.3.19.1+dfsg1-2.1+deb12u2 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-6+deb13u4 | 1:2.4.1+dfsg1-6+deb13u4 |
| dovecot | dovecot | >= 0 < 1:2.3.16+dfsg1-3ubuntu2.7 | 1:2.3.16+dfsg1-3ubuntu2.7 |
| dovecot | dovecot | >= 0 < 1:2.3.21+dfsg1-2ubuntu6.3 | 1:2.3.21+dfsg1-2ubuntu6.3 |
| dovecot | dovecot | >= 0 < 1:2.4.1+dfsg1-5ubuntu4.1 | 1:2.4.1+dfsg1-5ubuntu4.1 |
| open-xchange | dovecot | <= 2.3.0 | — |
| open-xchange_gmbh | ox_dovecot_pro | <= 2.3.0 | — |
| ubuntu | dovecot | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dovecot regression
vendor_ubuntu·2026-04-28·CVSS 5.3
CVE-2026-0394 [MEDIUM] Dovecot regression
Title: Dovecot regression
Summary: USN-8136-1 introduced a regression in Dovecot
USN-8136-1 fixed vulnerabilities in Dovecot. The update caused a regression
on Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this i
Ubuntu
Dovecot vulnerabilities
vendor_ubuntu·2026-03-31·CVSS 5.3
CVE-2026-27857 [MEDIUM] Dovecot vulnerabilities
Title: Dovecot vulnerabilities
Summary: Several security issues were fixed in Dovecot.
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. Thi
Red Hat
dovecot: Dovecot: Replay attack allows unauthorized login via observed One-Time Password (OTP) exchange
vendor_redhat·2026-03-27·CVSS 6.8
CVE-2026-27855 [MEDIUM] CWE-294 dovecot: Dovecot: Replay attack allows unauthorized login via observed One-Time Password (OTP) exchange
dovecot: Dovecot: Replay attack allows unauthorized login via observed One-Time Password (OTP) exchange
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
A flaw was found in Dovecot. Under specific conditions, if the authentication cache is enabled and the username is altered in the password database, Dovecot's One-Time Password (OTP) authent
Debian
CVE-2026-27855: dovecot - Dovecot OTP authentication is vulnerable to replay attack under specific conditi...
vendor_debian·2026·CVSS 6.8
CVE-2026-27855 [MEDIUM] CVE-2026-27855: dovecot - Dovecot OTP authentication is vulnerable to replay attack under specific conditi...
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
Scope: local
bookworm: resolved (fixed in 1:2.3.19.1+dfsg1-2.1+deb12u2)
bullseye: open
forky: open
sid: resolved (fixed in 1:2.4.3+dfsg1-1)
trixie: resolved (fixed in 1:2.4.1+dfsg1-6+deb13u4)
OSV
dovecot vulnerabilities
osv·2026-03-31·CVSS 5.3
CVE-2025-59028 [MEDIUM] dovecot vulnerabilities
dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled invalid base64 SASL data.
An attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 25.10. (CVE-2025-59028)
It was discovered that Dovecot script decode2text.sh incorrectly handled zip
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2025-59031)
It was discovered that Dovecot incorrectly handled certain AUTHENTICATE
requests. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-59032)
It was discovered that Dovecot incorrectly handled certain SQL based
authentication. An attacker could possibly use this issue to bypass
authentication. This issue only affected Ubuntu 25.10. (CVE-2026-24031)
It was dis
GHSA
GHSA-7923-h3mf-4442: Dovecot OTP authentication is vulnerable to replay attack under specific conditions
ghsa_unreviewed·2026-03-27
CVE-2026-27855 [MEDIUM] CWE-294 GHSA-7923-h3mf-4442: Dovecot OTP authentication is vulnerable to replay attack under specific conditions
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
OSV
CVE-2026-27855: Dovecot OTP authentication is vulnerable to replay attack under specific conditions
osv·2026-03-27·CVSS 6.8
CVE-2026-27855 [MEDIUM] CVE-2026-27855: Dovecot OTP authentication is vulnerable to replay attack under specific conditions
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
No detection rules found.
No public exploits indexed.
2026-03-27
Published