Replay Attack Vulnerability in Dovecot OTP Authentication by Open-Xchange
CVE-2026-27855

6.8MEDIUM

Key Information:

Vendor
CVE Published:
27 March 2026

What is CVE-2026-27855?

The Dovecot OTP authentication system has a vulnerability that allows for replay attacks under specific conditions. When the authentication cache is enabled and a user's credentials are modified in the passdb, there is a risk that the same OTP can be used multiple times. An attacker monitoring the OTP exchange could potentially log in as the user. To mitigate this risk, it is recommended to ensure that authentication occurs over secure connections, preferably utilizing the SCRAM protocol for enhanced security. If feasible, migrating to OAUTH2 is also advised to bolster protection against unauthorized access.

Affected Version(s)

OX Dovecot Pro 0 <= 2.3.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.