Description
There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:
- When safe filter is used with variable expansion, all following pipelines on the same string are
incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP
injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly
available exploits are known. (CVE-2026-27851)
- Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel
binding. This requires that the attacker is able to position itself between Dovecot and the client
connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM
proxy. Install fixed version. No publicly available exploits are known. (CVE-2026-33603)
- Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured
CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server
performance and bypass configured CPU time limits for Sieve scripts. Install fixed version, or
alternatively prevent direct access to Sieve scripts via ManageSieve or local access. No publicly
available exploits are known. (CVE-2026-40016)
- Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even
if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to
being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No
publicly available exploits are known. (CVE-2026-40020)
- An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in
CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left
open. In particular, the fix was for closing braces, but you could still use open braces to bypass the
limit. Using excessive bracing, attacker can cause memory usage up to configured memory limit. Install
fixed version, or configure vsz_limit for imap process to low value. No publicly available exploits are
known. (CVE-2026-42006)
Solution
Update the dovecot library and its related packages to version 2.4.4-r0 or later.
Plugin Details
Supported Sensors: Agentless Assessment
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 5/12/2026