Denial of Service Vulnerability in ManageSieve by Open-Xchange
CVE-2026-33605
7.5HIGH
Key Information:
- Vendor
Open-xchange Gmbh
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-33605?
A vulnerability in ManageSieve allows unauthenticated attackers to disrupt the login process by sending a malformed command. In high-security mode, only the attacker's connection is affected, while in high-performance mode, all connections associated with the ManageSieve login process can be terminated. This can lead to a denial of service for Sieve script management. Organizations are advised to restrict access to the ManageSieve service to trusted clients and update to non-vulnerable versions to mitigate this issue.
Affected Version(s)
OX Dovecot CE 2.3.0 < 2.4.5
OX Dovecot Pro 2.3.0 < 2.3.22.2
OX Dovecot Pro 3.0.0 < 3.0.7
