cbcvebase.
CVE-2026-27858
published 2026-03-27

CVE-2026-27858: Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force…

PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.79%
52.0th percentile
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)dovecot 1:2.3.19.1+dfsg1-2.1+deb12u2 (bookworm)
dovecotdovecot< 2.4.32.4.3
dovecotdovecot>= 0 < 1:2.3.19.1+dfsg1-2.1+deb12u21:2.3.19.1+dfsg1-2.1+deb12u2
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-6+deb13u41:2.4.1+dfsg1-6+deb13u4
dovecotdovecot>= 0 < 1:2.3.16+dfsg1-3ubuntu2.71:2.3.16+dfsg1-3ubuntu2.7
dovecotdovecot>= 0 < 1:2.3.21+dfsg1-2ubuntu6.31:2.3.21+dfsg1-2ubuntu6.3
dovecotdovecot>= 0 < 1:2.4.1+dfsg1-5ubuntu4.11:2.4.1+dfsg1-5ubuntu4.1
open-xchangedovecot< 2.3.22.12.3.22.1
open-xchangedovecot>= 3.0.0 < 3.0.53.0.5
open-xchangedovecot>= 3.1.0 < 3.1.43.1.4
open-xchange_gmbhox_dovecot_pro<= 2.3.0
ubuntudovecot

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.